Category: Secrets Security

JulesJacker: Fake npm Worm Impersonates Jules AI

JulesJacker: A Fake-PoC npm Worm That Impersonates Google’s Jules Agent — and Turns on the Sandbox Analyzing It

A fake npm worm impersonates Google’s Jules AI agent to steal repositories, abuse CI/CD pipelines,& attack analysis sandboxes. Take a look!
RuntimeBroker npm Typosquat Plants Crypto Clipper

RuntimeBroker: an npm Typosquat Plants a 40-Chain Crypto-Clipper as a Cross-OS \”System Runtime Helper”\

RuntimeBroker npm typosquat deploys a cross-OS crypto clipper targeting 40+ blockchains through fake runtime helper services.
AuditorTrap

AuditorTrap: A 22-Package Fake Crypto Security Guild on npm With Two Parallel Payloads

Read about AuditorTrap: Fake Web3 security tools on npm steal wallets, secrets, and API keys through malicious MCP packages & CI/CD payloads.
PhantomBot From Credential Theft to Botnet

PhantomBot: A Typosquat Campaign That Pivoted From Credential Theft to a Turnkey Botnet Kit

PhantomBot evolved from credential theft to a turnkey botnet in 48 hours. Discover the npm campaign behind it, read now!
AWS Lambda npm Dependency Confusion Attack The 24712-pl Campaign

AWS Lambda npm Dependency Confusion Attack: The 24712-pl Campaign

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
alone5511 npm Dependency Confusion Attack

alone5511 npm Dependency Confusion Attack

An npm dependency confusion attack used eight malicious packages to fingerprint hosts and send RCE telemetry to Telegram.
AI Security Risks in DevSecOps

AI Security Risks in DevSecOps: Code, Pipelines, and Agents

Explore AI security risks in DevSecOps and understand how they affect the software development lifecycle and automation processes.
12 min read
EVMDeFi npm Typosquatting Attack Steals Developer Keys

EVM/DeFi npm Typosquatting Attack Steals Developer Keys

A npm typosquatting attack used six malicious EVM/DeFi packages to steal developer keys, wallets, secrets, and .env files.
FauxCode When Your Reverse-Engineered Claude Code Quietly Routes Through the Attacker

FauxCode: Reverse-Engineered Claude Code Routes Through Attackers

FauxCode Claude Code npm malware used fake CLI packages to intercept API traffic through CA-bundle MITM and base URL hijacking.
DevTap npm Typosquatting Attack

DevTap npm Typosquatting Attack: Six Malicious Packages Target Developer Workstations

DevTap npm typosquatting attack used six malicious packages to spy on developer workstations and abuse npm trust.
LiteLLM Supply Chain Attack

LiteLLM Attack: How Xygeni Stops Secret Exposure Fast

LiteLLM attack exposed critical secrets. See how Xygeni detects, verifies, and revokes credentials before attackers use them.
7 min read
dockerfile secrets - dockerfile secrets environment variables

Dockerfile Secrets: Why Layers Keep Your Sensitive Data Forever

Stop leaks from Dockerfile secrets and dockerfile secrets environment variables. Protect builds from exposing credentials in image layers!