Suspected Hijacked Developer Accounts Spread npm Malware
ID: f7352bac-50a4-5dbd-9ed7-749cce923f37
STIX ID: report--f7352bac-50a4-5dbd-9ed7-749cce923f37
Feed Name: HackRead
Threat Score
Researchers discovered two malicious npm packages (sbx-mask and touch-adv) published via hijacked developer accounts; the packages steal environment variables (credentials, API tokens) and exfiltrate them to a tracked email address and via a webhook. Sonatype assigned tracking IDs, reported the incident to GitHub on 2026-03-19, and the packages were removed from the public registry, but affected developers should assume compromise and rotate credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
