Malicious NPM Packages Exfiltrate Hundreds of Developer SSH Keys via GitHub
ID: 81b95f4d-a0d9-5809-9891-eff718a69cbf
STIX ID: report--81b95f4d-a0d9-5809-9891-eff718a69cbf
Feed Name: The Hacker News
Two malicious npm packages, warbeast2000 and kodiak2k, were published and downloaded hundreds to low-thousands of times before removal; they use postinstall scripts to read SSH private keys (e.g., ~/.ssh/id_rsa), Base64-encode and exfiltrate them to attacker-controlled GitHub repositories, and later versions retrieve an archived Empire script capable of launching Mimikatz to dump credentials, demonstrating abuse of open-source package infrastructure for data theft and post-exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
