0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

AI-Generated npm Malware Exposes Own GitHub Token (infosecurity-magazine.com)

· 61d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Package disguised as archive deployment sync tool
  • Hardcoded GitHub token enabled direct researcher observation
  • 676 downloads before removal from npm

"A sloppy AI-generated npm package named mouse5212-super-formatter leaked its hardcoded GitHub token, enabling researchers to watch the operator's data theft. The infostealer, discovered by OX Security, uploaded files to an attacker-controlled repository. The package had 676 downloads before removal."

#AI-generated malware #npm supply chain attack #token leakage

Discussion Matrix

0 segments

no comments yet.