logo

Malicious NPM Packages Exfiltrate Hundreds of Developer SSH Keys via GitHub

ID: 81b95f4d-a0d9-5809-9891-eff718a69cbf

STIX ID: report--81b95f4d-a0d9-5809-9891-eff718a69cbf

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-01-23

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Two malicious npm packages, warbeast2000 and kodiak2k, were published and downloaded hundreds to low-thousands of times before removal; they use postinstall scripts to read SSH private keys (e.g., ~/.ssh/id_rsa), Base64-encode and exfiltrate them to attacker-controlled GitHub repositories, and later versions retrieve an archived Empire script capable of launching Mimikatz to dump credentials, demonstrating abuse of open-source package infrastructure for data theft and post-exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.