Npm Supply Chain Malware Attack Targets Developers With Worm-Like Propagation
ID: 6a1c7e9b-f817-552b-b2a6-7eb328d9d172
STIX ID: report--6a1c7e9b-f817-552b-b2a6-7eb328d9d172
Feed Name: Infosecurity Magazine (News)
Researchers discovered malicious npm packages (including versions of @automagik/genie and pgserve) that execute during installation to harvest environment secrets, CI/CD tokens, SSH keys, browser wallets and developer artifacts, exfiltrate data via HTTPS and Internet Computer Protocol endpoints, and propagate by stealing npm/PyPI credentials to republish compromised packages—mirroring prior worm-style supply-chain attacks and continuing to evolve as additional malicious versions appear.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
