AI-Generated npm Malware Exposes Own GitHub Token (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Package disguised as archive deployment sync tool
- Hardcoded GitHub token enabled direct researcher observation
- 676 downloads before removal from npm
"A sloppy AI-generated npm package named mouse5212-super-formatter leaked its hardcoded GitHub token, enabling researchers to watch the operator's data theft. The infostealer, discovered by OX Security, uploaded files to an attacker-controlled repository. The package had 676 downloads before removal."
#AI-generated malware
#npm supply chain attack
#token leakage
no comments yet.