Last Update: 08/01/2026 at 1:00 PM EST

Package Registries Target Developer Secrets

Coverage from BleepingComputer, Security Boulevard, and others

Articles

17

Active Days

115

The Topic

Package Registries Target Developer Secrets topic image

Attackers are repeatedly compromising or impersonating packages on npm and PyPI to steal developer credentials, cloud secrets, CI/CD tokens, and cryptocurrency wallet data. Several campaigns use trusted publishing accounts, malicious installation hooks, typosquatted dependencies, or self-propagation to reach additional packages and repositories. The activity affects enterprise tooling, AI software, payment integrations, and widely downloaded development ecosystems, while attribution remains mixed between TeamPCP-linked malware, other threat actors using leaked code, and a Microsoft-attributed North Korean operation.

First Article: 03/23/26

Latest Article: 07/15/26

Summary

  • Compromised packages used preinstall or postinstall hooks to execute credential-stealing payloads on developer systems and CI runners.
  • Targets included npm and PyPI publishing tokens, GitHub and cloud credentials, SSH keys, CI/CD secrets, Kubernetes and Docker configurations, and cryptocurrency wallets.
  • Several campaigns attempted to propagate by using stolen publishing rights to modify additional packages or repositories.
  • The Red Hat incident affected 32 packages and 96 versions, while the Mastra campaign reached more than 140 packages in its scope.
  • Attack techniques included CI runner memory scanning, GitHub-based data dead drops, trusted publishing through GitHub Actions OIDC, and typosquatted dependencies.
  • Researchers linked some activity to TeamPCP or leaked Shai-Hulud code, while Microsoft attributed the Mastra campaign to North Korea-linked Sapphire Sleet with high confidence.
  • The affected ecosystems span enterprise development tooling, AI packages, payment SDKs, and common JavaScript dependencies.

History

07/25/2026

The story now emphasizes a broader set of credential-theft techniques and a wider operational footprint, including enterprise tooling, AI software, payment integrations, and common JavaScript dependencies. It also adds more specific campaign details, especially the Red Hat package compromise scale and the use of CI runner memory scanning and GitHub-based dead drops.

07/24/2026

The story broadens from npm-only credential theft into a wider cross-ecosystem campaign that now includes PyPI and self-propagating malware behavior. Attribution also sharpens, with Microsoft tying the Mastra campaign to North Korean Sapphire Sleet and researchers linking some activity to leaked Shai-Hulud malware.

Full History

Featured

Timeline: 115 Days

Mar 23Apr 13May 4Jun 1Jun 22Jul 13

Additional Articles

⭐⭐⭐⭐⭐

BleepingComputer / Lawrence Abrams06-01-2026
Aikido and OX Security detected Miasma backdoors in Red Hat npm packages, and Red Hat removed the affected packages after credential-stealing activity.
BleepingComputer / Lawrence Abrams06-20-2026
Microsoft attributed a Mastra npm maintainer account hijack on June 19 to Sapphire Sleet after malicious updates across more than 140 npm packages deployed credential and crypto-wallet-stealing malware.
BleepingComputer / Bill Toulas07-08-2026
Socket reported malicious npm and PyPI packages distributed fake Paysafe SDKs that stole API keys and access tokens via AWS-hosted command and control.
BleepingComputer / Bill Toulas07-15-2026
Attackers compromised AsyncAPI GitHub repositories on July 14, publishing trojanized npm packages through GitHub Actions and OIDC despite later removal.
BleepingComputer / Bill Toulas03-30-2026
Security researchers identified an npm compromise of the Axios maintainer that enabled malicious axios package versions delivering a remote access trojan across Linux, Windows, and macOS.

⭐⭐⭐

BleepingComputer / Bill Toulas06-09-2026
SAP released June 2026 patches for NetWeaver and Commerce Cloud vulnerabilities, including critical SAML authentication bypass and unauthenticated memory corruption.
BleepingComputer / Bill Toulas07-13-2026
Socket analyzed a Jscrambler npm supply-chain compromise in which malicious releases executed via the preinstall hook and targeted sensitive data.
BleepingComputer / Bill Toulas03-23-2026
Socket and OpenSourceMalware reported that TeamPCP compromised Aqua Security's Trivy GitHub pipeline in March 2020s, leading to malicious Docker Hub artifacts and repository tampering.
BleepingComputer / Lawrence Abrams04-03-2026
Axios maintainers reported an npm supply chain incident in which a North Korea-nexus actor compromised maintainer accounts and published malicious versions that installed a remote access trojan.
BleepingComputer / Lawrence Abrams04-13-2026
OpenAI rotated macOS code-signing certificates after a March 31, 2026 GitHub Actions workflow executed a compromised Axios package used in a supply chain attack.
Security Boulevard / Ron Popov03-30-2026
Axios npm versions 1.14.1 and 0.30.4 were compromised in a maintainer-account hijack, leading to postinstall execution of a dropper and RAT payload and requiring supply-chain scanning and credential rotation.
Security Boulevard / Ron Popov03-30-2026
Attackers compromised Axios npm package releases in 1.14.1 and 0.30.4 by using plain-crypto-js postinstall execution, enabling remote access trojans and credential theft risk.
Security Boulevard / Ron Popov03-30-2026
Axios npm package releases 1.14.1 and 0.30.4 were compromised by a maintainer hijack, adding a postinstall-based malicious dependency that enables remote access trojan deployment.
Securityboulevard / Ron Popov03-30-2026
Axios npm versions 1.14.1 and 0.30.4 were compromised in a maintainer-hijack supply-chain attack on March 31, 2026, with installation-time trojan delivery and credential risk.