logo

Suspected Hijacked Developer Accounts Spread npm Malware

ID: f7352bac-50a4-5dbd-9ed7-749cce923f37

STIX ID: report--f7352bac-50a4-5dbd-9ed7-749cce923f37

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-03-26

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Researchers discovered two malicious npm packages (sbx-mask and touch-adv) published via hijacked developer accounts; the packages steal environment variables (credentials, API tokens) and exfiltrate them to a tracked email address and via a webhook. Sonatype assigned tracking IDs, reported the incident to GitHub on 2026-03-19, and the packages were removed from the public registry, but affected developers should assume compromise and rotate credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.