Category: Secrets Security

PhantomSync: npm Crypto Packages Hide Wallet Stealer

PhantomSync: eight crypto-developer npm packages hide a delayed, self-persisting dropper

FauxUV: Fake PyPI uv Packages Open Jupyter to the Web

FauxUV: fake PyPI uv helpers that open an unauthenticated Jupyter server to the internet

forge-jsxy npm Infostealer: IOCs & Detection Guide

forge-jsxy: The npm Infostealer That Keeps Changing Its Name

GhostTracker: npm Trojan Rebranded in 74 Minutes — Same C2

GhostTracker: an npm trojan that rebranded within hours of takedown — and kept the same C2

SkillLeak, Browser Credential Theft via MCP Skill

SkillLeak: A Browser-Credential Decryptor Delivered Through an MCP Skill

DeviceDoor npm Package Shipping a Microsoft 365 Device-Code Phishing Framework

DeviceDoor: a public npm package shipping a Microsoft 365 device-code phishing and bulk-mail framework

CryptoDAO Confusion: npm Packages Harvesting CI/CD and Crypto Secrets

CryptoDAO Confusion: eleven npm packages, one payload, harvesting CI/CD and crypto-wallet secrets

Permission Slip: npm Package Hiding Cloud & System Threats

Permission Slip: An npm “Authorized Research” Cover Story Hiding Cloud-Metadata Probes and SYSTEM Persistence

Ectoplasm npm Install Hooks That Steal AWS Credentials

Ectoplasm: npm install hooks that harvest AWS credentials behind a container-only trigger

SeedSweep: Ten Malicious npm Crypto Packages

SeedSweep: Ten Crypto-Themed npm Packages That Only Run When No One Is Watching

PairLoop: Hidden Remote-Control Panel in npm Package

PairLoop: One npm Package, Seventy Versions, and a Hidden Windows Remote-Control Panel

ConsentMask The npm Package Hiding Developer Identity Harvesting

ConsentMask: An npm Package That Wears a Telemetry Consent Banner Over Developer-Identity Harvesting