logo

AI-Generated npm Malware Leaks Its Own GitHub Token

ID: 74929019-811b-5149-9b42-7a9b22ef8d54

STIX ID: report--74929019-811b-5149-9b42-7a9b22ef8d54

Feed Name: Infosecurity Magazine (News)

Threat Score
55/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

...
...

A malicious npm package named mouse5212-super-formatter masqueraded as an internal sync utility but contained post-install code that authenticated to GitHub (using a hardcoded token), created a repo, and recursively uploaded local files to the attacker's repository; researchers observed multiple theft sessions and advise revoking tokens and treating affected files as compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.