logo

New npm supply-chain attack self-spreads to steal auth tokens

ID: bb8885e7-4fa3-54e0-97b3-ad9058051cd6

STIX ID: report--bb8885e7-4fa3-54e0-97b3-ad9058051cd6

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Bill Toulas

...
...

A new supply-chain worm targeting the npm ecosystem was observed injecting credential- and secret-stealing code into compromised packages (16 Namastex-related packages noted). The malicious code exfiltrates tokens, API keys, SSH keys, cloud/CI/registry/LLM credentials, Kubernetes/Docker configs, and browser-stored wallets, and it propagates by using discovered publish tokens to republish infected packages (with a similar PyPI technique possible); researchers advise removing affected versions, rotating secrets, and using provided IOCs to detect and remediate infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.