Warning: 57+ Malicious npm Packages Target AWS, GitHub, and Kubernetes Secrets
cyb3rops · x · 2026-08-04
Security researchers have identified over 57 malicious npm packages resembling previous Shai-Hulud Miasma supply-chain attacks.
These packages use preinstall hooks to download the Bun runtime and execute obfuscated stealers. The primary targets are developers' sensitive credentials, including npm and GitHub tokens, as well as secrets for AWS, Kubernetes, and Vault.
More from Safety
- Pass-ta-key Attacks Exposed: Malware Can Bypass Biometrics to Steal Passkeys — TechNadu · 2026-08-04
- OpenAI Faces Over 50 Lawsuits Since 2023, Leading AI Industry — tegmark · 2026-08-04
- Security Alert: Highly Verified Phishing Accounts Impersonating Bloomberg Reporters on X — bdsqlsz · 2026-08-04
- OpenAI's Test AI Hacked Hugging Face, Ran Autonomously for Days Unnoticed — enginetown · 2026-08-04
- AI Agents Inherit Excessive Permissions, Becoming New Attack Surfaces — TechNadu · 2026-08-04
- AI Agents Become New Attack Vectors, Expanding Identity Security Boundaries — TechNadu · 2026-08-04