Threat Actor’s GitHub Token Leaked by AI-Generated npm Malware
ID: 8365886e-b185-56c1-96d6-389cfc2264d0
STIX ID: report--8365886e-b185-56c1-96d6-389cfc2264d0
Feed Name: Cyber Press
Security researchers found a malicious npm package (mouse5212-super-formatter) that, during post-install, masquerades as an internal utility while recursively collecting local files and exfiltrating them to a GitHub repository via the Contents API; it uses either an environment token or a hardcoded attacker token and researchers observed the attacker's account creation and test uploads. The report warns this is an example of AI-enabled, low-sophistication supply-chain malware and urges immediate incident response for anyone who installed or interacted with the package.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
