logo

Threat Actor’s GitHub Token Leaked by AI-Generated npm Malware

ID: 8365886e-b185-56c1-96d6-389cfc2264d0

STIX ID: report--8365886e-b185-56c1-96d6-389cfc2264d0

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-28

Date Updated: 2026-05-28

Author: Varshini

...
...

Security researchers found a malicious npm package (mouse5212-super-formatter) that, during post-install, masquerades as an internal utility while recursively collecting local files and exfiltrating them to a GitHub repository via the Contents API; it uses either an environment token or a hardcoded attacker token and researchers observed the attacker's account creation and test uploads. The report warns this is an example of AI-enabled, low-sophistication supply-chain malware and urges immediate incident response for anyone who installed or interacted with the package.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.