Cybersecurity Startup Publishes Infostealers to NPM
ID: c35da613-d229-5e12-ba1f-35a8b4341358
STIX ID: report--c35da613-d229-5e12-ba1f-35a8b4341358
Feed Name: OpenSourceMalware Blog
Date Published: 2026-07-09
Date Updated: 2026-08-06
Author: c0a15726-c5b1-4b0d-85e6-fe15553df9e2
A coordinated supply-chain campaign published multiple typosquatted npm packages impersonating AI and security tooling; install-time scripts (preinstall/postinstall) silently collected developer identity and environment metadata (hostnames, git emails, SSH key comments, reflog committer emails, cloud profiles, project metadata, CI indicators) and exfiltrated it via Google Cloud Run (project 228835561205) to endpoints in europe-west1 and us-central1, with roughly 20k downloads across packages. The packages were iteratively refined (April -> June), included social-engineering elements (typosquats, backfilled versions, plausible README/opt-outs), and were linked to a single npm account associated with a known cybersecurity startup founder; indicators and mitigations (ignore install-time scripts, monitor run.app egress) are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
