logo

AI-Generated npm Malware Leaks Hacker’s Private GitHub Token

ID: 4a581dbb-14a0-5a8d-827a-767f3f6b370c

STIX ID: report--4a581dbb-14a0-5a8d-827a-767f3f6b370c

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-05-28

Date Updated: 2026-05-28

Author: Mayura Kathir

...
...

A malicious npm package named mouse5212-super-formatter, identified by OX Security, operates as an AI-generated infostealer that recursively scans the /mnt/user-data directory, base64-encodes discovered files, and uploads them to attacker-controlled GitHub repositories via the Contents API. The operator mistakenly hardcoded a private GitHub token, allowing researchers to observe roughly seven active exfiltration events and trace attacker infrastructure; the package remains live on npm with all versions affected. Immediate remediation recommended: revoke tokens, audit exposed systems, and monitor for automated GitHub uploads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.