[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4QEBNNWpaH37xdWwn68MSboFeVlc_tYWTVSEsHhxR8Q":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"919962c2-c9cb-4dc7-8590-ae0ef8992bb8","malicious-npm-packages-steal-cloud-credentials-and-self-propagate-via-stolen-tokens","0e5d4a09-fdb2-45b2-bbb1-33d2404daf6d","Malicious npm Packages Steal Cloud Credentials and Self-Propagate via Stolen Tokens","Attackers compromised at least ten widely-used npm packages by injecting a preinstall hook that silently downloads a runtime and executes an obfuscated payload to harvest cloud and CI\u002FCD credentials. The stolen npm tokens were then used to trojanize additional packages, creating a self-propagating attack that amplifies impact across the entire dependency graph. With tens of millions of weekly downloads through transitive dependencies, even developers who never directly install these packages are at risk. This incident highlights the critical danger of trusting third-party package maintainer accounts without additional verification — a single compromised account can cascade into widespread infrastructure exposure.","**Immediate actions:**\n- Audit all projects for direct or transitive dependencies on keyv, cacheable, or any Jaredwray-maintained packages and pin to known-safe versions or remove them.\n- Rotate all cloud, CI\u002FCD, and npm credentials immediately if any affected package versions were installed in your build pipelines.\n- Run secret-scanning tools (e.g., Truffleog, GitLeaks) across your repositories and CI environments to detect any harvested credentials.\n\n**Detection measures:**\n- Enable runtime behavior monitoring in your CI\u002FCD pipelines to alert on unexpected outbound network calls or binary downloads during package installation.\n- Implement a software composition analysis (SCA) tool with real-time malicious-package detection (e.g., Socket, Snyk, Dependabot) that flags preinstall\u002Fpostinstall scripts.\n- Monitor npm audit logs and dependency lock files for unexpected version changes or newly introduced lifecycle scripts.\n\n**Long-term improvements:**\n- Enforce a policy of locking all dependencies to exact versions via lock files (package-lock.json, yarn.lock) and verify integrity hashes before deploying.\n- Require multi-factor authentication and token scoping for all npm publish accounts, and consider using a private registry proxy (e.g., Artifactory, Verdaccio) to vet packages before they reach developers.\n- Establish a formal third-party dependency risk review process that evaluates maintainer account security posture and package change velocity as part of your SDLC.",[12,13,14,15,16,17,18,19,20],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-161r1: Cybersecurity Supply Chain Risk Management","NIST SP 800-218 SSDF: PW.4 – Reuse Existing, Well-Secured Software","NIST SP 800-53 SA-12: Supply Chain Protection","NIST SP 800-53 IA-5: Authenticator Management (credential rotation)","SLSA Supply Chain Levels for Software Artifacts – Level 3 (verified provenance)","OWASP Top 10 A06:2021 – Vulnerable and Outdated Components","GDPR Article 32: Security of Processing (where PII may be exposed via harvested credentials)","published","2026-08-04T12:22:54.070863+00:00","2026-08-04T12:22:53.766+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fpopular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain?utm_medium=feed","popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active--541eac","Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[48],{"id":49,"date":50,"edition":51,"title":52,"audio_url":53},"abd84ae4-c524-4918-9354-c389de7e7457","2026-08-04","afternoon","ThreatNoir Afternoon Brief — August 4","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-04\u002Fthreatnoir-afternoon-brief-2026-08-04.mp3"]