Malicious npm packages harvest crypto keys and secrets

Nineteen malicious packages on the npm registry are spreading a worm known as SANDWORM_MODE. These packages steal crypto keys, CI secrets, API tokens, and AI API keys. The theft occurs through MCP injection.

Security researchers have identified 19 malicious npm packages that are actively harvesting sensitive information from developers' systems. According to reports, these packages propagate a worm called SANDWORM_MODE, which targets crypto keys, continuous integration (CI) secrets, API tokens, and AI API keys.

The malicious software employs MCP injection as its primary method to extract and exfiltrate this data. npm, the popular package manager for JavaScript and Node.js, serves as the distribution platform for these threats, potentially compromising developers who install the affected packages unknowingly.

This incident highlights ongoing risks in open-source software ecosystems, where supply chain attacks can lead to widespread data breaches. No specific details on the exact names of the 19 packages or the total number of affected users were provided in the available information.

Developers are advised to review their dependencies and use tools to scan for vulnerabilities in npm packages to mitigate such risks.

Verwandte Artikel

Developer platform Socket has identified a malware known as TrapDoor that is targeting crypto and AI developers.

Von KI berichtet

Seventy-three Microsoft open source packages were compromised late last week with malware that steals credentials from cloud services and developer tools. The malicious code activates when opened in AI coding agents.

Dienstag, 16. Juni 2026, 20:05 Uhr

Arch Linux disables new AUR registrations after malware waves

Samstag, 13. Juni 2026, 16:49 Uhr

Malware infects 1579 packages in Arch Linux AUR

Montag, 25. Mai 2026, 23:10 Uhr

GitHub hit with another major attack by Megalodon

Dienstag, 05. Mai 2026, 12:10 Uhr

Daemon Tools app hit by monthlong supply-chain attack

Dienstag, 31. März 2026, 11:54 Uhr

Anthropic's Claude Code CLI source code leaks online

Diese Website verwendet Cookies

Wir verwenden Cookies für Analysen, um unsere Website zu verbessern. Lesen Sie unsere Datenschutzrichtlinie für weitere Informationen.
Ablehnen