Package Registries Target Developer Secrets
Coverage from BleepingComputer, Security Boulevard, and others
Articles
17
Active Days
115
The Topic

Attackers are repeatedly compromising or impersonating packages on npm and PyPI to steal developer credentials, cloud secrets, CI/CD tokens, and cryptocurrency wallet data. Several campaigns use trusted publishing accounts, malicious installation hooks, typosquatted dependencies, or self-propagation to reach additional packages and repositories. The activity affects enterprise tooling, AI software, payment integrations, and widely downloaded development ecosystems, while attribution remains mixed between TeamPCP-linked malware, other threat actors using leaked code, and a Microsoft-attributed North Korean operation.
First Article: 03/23/26
Latest Article: 07/15/26
Summary
- Compromised packages used preinstall or postinstall hooks to execute credential-stealing payloads on developer systems and CI runners.
- Targets included npm and PyPI publishing tokens, GitHub and cloud credentials, SSH keys, CI/CD secrets, Kubernetes and Docker configurations, and cryptocurrency wallets.
- Several campaigns attempted to propagate by using stolen publishing rights to modify additional packages or repositories.
- The Red Hat incident affected 32 packages and 96 versions, while the Mastra campaign reached more than 140 packages in its scope.
- Attack techniques included CI runner memory scanning, GitHub-based data dead drops, trusted publishing through GitHub Actions OIDC, and typosquatted dependencies.
- Researchers linked some activity to TeamPCP or leaked Shai-Hulud code, while Microsoft attributed the Mastra campaign to North Korea-linked Sapphire Sleet with high confidence.
- The affected ecosystems span enterprise development tooling, AI packages, payment SDKs, and common JavaScript dependencies.
History
The story now emphasizes a broader set of credential-theft techniques and a wider operational footprint, including enterprise tooling, AI software, payment integrations, and common JavaScript dependencies. It also adds more specific campaign details, especially the Red Hat package compromise scale and the use of CI runner memory scanning and GitHub-based dead drops.
The story broadens from npm-only credential theft into a wider cross-ecosystem campaign that now includes PyPI and self-propagating malware behavior. Attribution also sharpens, with Microsoft tying the Mastra campaign to North Korean Sapphire Sleet and researchers linking some activity to leaked Shai-Hulud malware.
