Malicious npm Packages Steal Crypto Keys, CI Secrets, and API Tokens
Cybersecurity researchers have uncovered an active supply chain attack leveraging at least 19 malicious npm packages to harvest credentials, cryptocurrency private keys, CI secrets, and API tokens from developer environments. The campaign, named SANDWORM_MODE by Socket, exhibits worm like behavior similar to earlier Shai Hulud style attacks. The malware is designed not only to extract sensitive […]
Malicious npm Packages Steal Crypto Keys, CI Secrets, and API Tokens Read More »









