History
07/25/20260 new articles
The story now emphasizes a broader set of credential-theft techniques and a wider operational footprint, including enterprise tooling, AI software, payment integrations, and common JavaScript dependencies. It also adds more specific campaign details, especially the Red Hat package compromise scale and the use of CI runner memory scanning and GitHub-based dead drops.
07/24/20260 new articles
The story broadens from npm-only credential theft into a wider cross-ecosystem campaign that now includes PyPI and self-propagating malware behavior. Attribution also sharpens, with Microsoft tying the Mastra campaign to North Korean Sapphire Sleet and researchers linking some activity to leaked Shai-Hulud malware.
- PyPI is now targeted in addition to npm.
- Self-propagating malware is spreading via stolen publishing credentials.
- Shai-Hulud-derived malware has been reused or modified after leakage.
- Mastra is attributed by Microsoft to North Korean Sapphire Sleet.
- Some campaigns now impersonate payment SDKs and use fake SDK lures.
07/24/20263 new articles
The story has broadened from npm maintainer hijacks into a wider, more varied supply-chain pattern involving CI/CD workflow abuse, trusted publishing, and compromise across adjacent package and distribution ecosystems. The new framing emphasizes repeated secret-theft campaigns against developers and downstream software pipelines, not just malicious npm releases.
- CI/CD workflow abuse is now a major attack path.
- The story now spans PyPI, Docker Hub, and code-signing workflows.
- Specific secret types targeted include npm tokens and SSH keys.
- Some malicious versions were removed quickly after publication.
- Several incidents now carry TeamPCP or UNC1069 attribution.
06/11/20263 new articles
The story broadens from an Axios-centered npm compromise wave into a wider pattern of enterprise and tooling compromises across npm, GitHub workflows, and build pipelines. New coverage adds Red Hat and Trivy, and shows downstream operational fallout like OpenAI certificate rotation and self-propagating package abuse.
- GitHub workflows are now described as a compromise surface.
- Red Hat appears as a newly highlighted target.
- Trivy is newly included as a supply-chain victim.
- OpenAI rotated certificates after exposure.
- Self-propagating package republishing is newly reported.
05/11/2026Topic Formed
This cluster is centered on a wave of npm supply-chain compromises in which attacker access to maintainer accounts or build pipelines enabled malicious package publication, install-time execution, and credential theft. The strongest current signal is operational: poisoned packages, secret-stealing payloads, and downstream incident response actions such as secret rotation, host quarantine, package removal, and certificate revocation. Coverage is dominated by live security response around Axios, with later articles extending the pattern to broader npm ecosystem compromise and CI/CD secret harvesting.