Category: Secrets Security

PhantomSync: npm Crypto Packages Hide Wallet Stealer

PhantomSync: eight crypto-developer npm packages hide a delayed, self-persisting dropper

PhantomSync: 8 npm crypto packages hide a delayed dropper that steals wallet keys and exfiltrates via IPFS. IOCs and detection guide.
FauxUV: Fake PyPI uv Packages Open Jupyter to the Web

FauxUV: fake PyPI uv helpers that open an unauthenticated Jupyter server to the internet

FauxUV: fake PyPI uv helper packages install a passwordless JupyterLab server, then expose it to the internet via reverse tunnel.
forge-jsxy npm Infostealer: IOCs & Detection Guide

forge-jsxy: The npm Infostealer That Keeps Changing Its Name

Renamed npm infostealer forge-jsxy → pinokio-redis steals crypto wallets & credentials. IOCs, timeline, and defender guidance inside.
GhostTracker: npm Trojan Rebranded in 74 Minutes — Same C2

GhostTracker: an npm trojan that rebranded within hours of takedown — and kept the same C2

GhostTracker rebranded 74 minutes after takedown, same C2, new names. Do you know how the npm trojan works and what to block first?
SkillLeak, Browser Credential Theft via MCP Skill

SkillLeak: A Browser-Credential Decryptor Delivered Through an MCP Skill

SkillLeak hides a Chrome/Edge password decryptor inside an MCP skill, not an install hook. Learn how it works and what defenders should check.
DeviceDoor npm Package Shipping a Microsoft 365 Device-Code Phishing Framework

DeviceDoor: a public npm package shipping a Microsoft 365 device-code phishing and bulk-mail framework

DeviceDoor hides a device-code phishing framework inside an npm package. Learn how it works and how to defend against it.
CryptoDAO Confusion: npm Packages Harvesting CI/CD and Crypto Secrets

CryptoDAO Confusion: eleven npm packages, one payload, harvesting CI/CD and crypto-wallet secrets

CryptoDAO Confusion: eleven npm packages at version 99.99.99 harvesting CI/CD tokens, cloud keys, and crypto wallet secrets on postinstall.
Permission Slip: npm Package Hiding Cloud & System Threats

Permission Slip: An npm “Authorized Research” Cover Story Hiding Cloud-Metadata Probes and SYSTEM Persistence

Permission Slip: six malicious npm packages hide cloud-metadata probes and Windows SYSTEM persistence behind a fake research disclaimer.
Ectoplasm npm Install Hooks That Steal AWS Credentials

Ectoplasm: npm install hooks that harvest AWS credentials behind a container-only trigger

Five npm packages silently harvest AWS credentials and Secrets Manager key, but only inside containers. How Ectoplasm evades detection.
SeedSweep: Ten Malicious npm Crypto Packages

SeedSweep: Ten Crypto-Themed npm Packages That Only Run When No One Is Watching

SeedSweep: 10 npm packages stealing crypto wallets and SSH keys via Telegram. Silent in CI, deadly on dev machines. Dive in!
PairLoop: Hidden Remote-Control Panel in npm Package

PairLoop: One npm Package, Seventy Versions, and a Hidden Windows Remote-Control Panel

PairLoop uncovers how a suspicious npm package deployed persistence, browser surveillance, and a hidden Windows remote-control panel.
ConsentMask The npm Package Hiding Developer Identity Harvesting

ConsentMask: An npm Package That Wears a Telemetry Consent Banner Over Developer-Identity Harvesting

Take a look at ConsentMask, the npm package that harvested developer identities, GitHub accounts, and CI data via postinstall.