Category: Attacks Analysis

Slopsquatting Attacks

Slopsquatting Attacks: How an AI Mistake Became a New Way Into Your Software Supply Chain

Slopsquatting attacks explained: how AI package hallucinations become real malware. See the evolution and practical prevention steps.
9 min read
forge-jsxy npm Infostealer: IOCs & Detection Guide

forge-jsxy: The npm Infostealer That Keeps Changing Its Name

Renamed npm infostealer forge-jsxy → pinokio-redis steals crypto wallets & credentials. IOCs, timeline, and defender guidance inside.
GhostTracker: npm Trojan Rebranded in 74 Minutes — Same C2

GhostTracker: an npm trojan that rebranded within hours of takedown — and kept the same C2

GhostTracker rebranded 74 minutes after takedown, same C2, new names. Do you know how the npm trojan works and what to block first?
SkillLeak, Browser Credential Theft via MCP Skill

SkillLeak: A Browser-Credential Decryptor Delivered Through an MCP Skill

SkillLeak hides a Chrome/Edge password decryptor inside an MCP skill, not an install hook. Learn how it works and what defenders should check.
DeviceDoor npm Package Shipping a Microsoft 365 Device-Code Phishing Framework

DeviceDoor: a public npm package shipping a Microsoft 365 device-code phishing and bulk-mail framework

DeviceDoor hides a device-code phishing framework inside an npm package. Learn how it works and how to defend against it.
CryptoDAO Confusion: npm Packages Harvesting CI/CD and Crypto Secrets

CryptoDAO Confusion: eleven npm packages, one payload, harvesting CI/CD and crypto-wallet secrets

CryptoDAO Confusion: eleven npm packages at version 99.99.99 harvesting CI/CD tokens, cloud keys, and crypto wallet secrets on postinstall.
Permission Slip: npm Package Hiding Cloud & System Threats

Permission Slip: An npm “Authorized Research” Cover Story Hiding Cloud-Metadata Probes and SYSTEM Persistence

Permission Slip: six malicious npm packages hide cloud-metadata probes and Windows SYSTEM persistence behind a fake research disclaimer.
Ectoplasm npm Install Hooks That Steal AWS Credentials

Ectoplasm: npm install hooks that harvest AWS credentials behind a container-only trigger

Five npm packages silently harvest AWS credentials and Secrets Manager key, but only inside containers. How Ectoplasm evades detection.
SeedSweep: Ten Malicious npm Crypto Packages

SeedSweep: Ten Crypto-Themed npm Packages That Only Run When No One Is Watching

SeedSweep: 10 npm packages stealing crypto wallets and SSH keys via Telegram. Silent in CI, deadly on dev machines. Dive in!
PairLoop: Hidden Remote-Control Panel in npm Package

PairLoop: One npm Package, Seventy Versions, and a Hidden Windows Remote-Control Panel

PairLoop uncovers how a suspicious npm package deployed persistence, browser surveillance, and a hidden Windows remote-control panel.
ConsentMask The npm Package Hiding Developer Identity Harvesting

ConsentMask: An npm Package That Wears a Telemetry Consent Banner Over Developer-Identity Harvesting

Take a look at ConsentMask, the npm package that harvested developer identities, GitHub accounts, and CI data via postinstall.
JulesJacker: Fake npm Worm Impersonates Jules AI

JulesJacker: A Fake-PoC npm Worm That Impersonates Google’s Jules Agent — and Turns on the Sandbox Analyzing It

A fake npm worm impersonates Google’s Jules AI agent to steal repositories, abuse CI/CD pipelines,& attack analysis sandboxes. Take a look!