logo

Hackers Compromise 170 npm Packages to Steal GitHub, npm, AWS, and Kubernetes Secrets

ID: a2bdac87-b1d1-5893-a145-518249bcf092

STIX ID: report--a2bdac87-b1d1-5893-a145-518249bcf092

Feed Name: cybersecurityNews.com

Threat Score
92/100

Date Published: 2026-05-14

Date Updated: 2026-05-22

Author: Tushar Subhra Dutta

...
...

A coordinated supply-chain campaign attributed to TeamPCP compromised over 170 npm and two PyPI packages to deploy credential‑stealing, self‑propagating malware that abuses GitHub Actions/workflows to harvest and exfiltrate secrets via GitHub dead‑drop repositories and includes a dead‑man wiper; the report provides extensive IoCs and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.