DevSec Station

← DevSec Station22 apr · 2 min

NPM Supply Chain Attack: Active Worm Stealing Tokens, SSH Keys, and Credentials

NPM Supply Chain Attack: Active Worm Stealing Tokens, SSH Keys, and Credentials22 apr2 min

🚨 Emergency DevSec Station update. There’s an active npm supply chain attack happening right now. Malicious npm packages are running install scripts that quietly steal: • SSH keys • AWS credentials • GitHub tokens • Browser passwords • Crypto wallets From there, the attack uses your npm publish token to spread into every package you maintain. That’s how this turns into a worm across the npm ecosystem. This is not theoretical. It’s already in the wild. 👉 Immediate...