logo

Npm Supply Chain Malware Attack Targets Developers With Worm-Like Propagation

ID: 6a1c7e9b-f817-552b-b2a6-7eb328d9d172

STIX ID: report--6a1c7e9b-f817-552b-b2a6-7eb328d9d172

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

...
...

Researchers discovered malicious npm packages (including versions of @automagik/genie and pgserve) that execute during installation to harvest environment secrets, CI/CD tokens, SSH keys, browser wallets and developer artifacts, exfiltrate data via HTTPS and Internet Computer Protocol endpoints, and propagate by stealing npm/PyPI credentials to republish compromised packages—mirroring prior worm-style supply-chain attacks and continuing to evolve as additional malicious versions appear.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.