Warning: 57+ Malicious npm Packages Target AWS, GitHub, and Kubernetes Secrets

cyb3rops · x · 2026-08-04

Security researchers have identified over 57 malicious npm packages resembling previous Shai-Hulud Miasma supply-chain attacks.

These packages use preinstall hooks to download the Bun runtime and execute obfuscated stealers. The primary targets are developers' sensitive credentials, including npm and GitHub tokens, as well as secrets for AWS, Kubernetes, and Vault.

Original post →

More from Safety

Safety channel →