New npm supply-chain attack self-spreads to steal auth tokens
ID: bb8885e7-4fa3-54e0-97b3-ad9058051cd6
STIX ID: report--bb8885e7-4fa3-54e0-97b3-ad9058051cd6
Feed Name: Bleeping Computer
A new supply-chain worm targeting the npm ecosystem was observed injecting credential- and secret-stealing code into compromised packages (16 Namastex-related packages noted). The malicious code exfiltrates tokens, API keys, SSH keys, cloud/CI/registry/LLM credentials, Kubernetes/Docker configs, and browser-stored wallets, and it propagates by using discovered publish tokens to republish infected packages (with a similar PyPI technique possible); researchers advise removing affected versions, rotating secrets, and using provided IOCs to detect and remediate infections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
