Find notable cyber news and cases, enriched with sources, timelines, and signals.

Npm supply-chain worm that steals publishing tokens and self-propagates

Malware Activity
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

A new npm supply-chain worm is stealing developer publishing tokens and using them to self-propagate through republished packages, creating the risk of broader compromise across software distribution. The malicious code can also exfiltrate API keys, SSH keys, and other secrets from developer environments. StepSecurity says the same behavior can extend into PyPI when Python credentials are present.

Related Happenings

AsyncAPI malicious npm package supply-chain malware

Malware Activity
H score21 First: 15.07.2026 18:37 Last: 15.07.2026 18:37 Sources 1

About this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...

Compromised @asyncapi npm packages distributing the Miasma loader

Malware Activity
H score29 First: 15.07.2026 12:16 Last: 15.07.2026 12:16 Sources 1

About this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....

AsyncAPI repositories and npm publishing workflow hit by network compromise

Incident
H score27 First: 15.07.2026 12:16 Last: 15.07.2026 12:16 Sources 1

About this happening: The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...

Jscrambler 8.14.0 malicious preinstall infostealer release

Malware Activity
H score9 First: 11.07.2026 20:59 Last: 11.07.2026 20:59 Sources 1

About this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...

Malicious npm and PyPI payment SDK typosquat packages

Malware Activity
H score40 First: 09.07.2026 18:09 Last: 09.07.2026 18:09 Sources 1

About this happening: The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...

Timeline

  1. 22.04.2026 15:57 2 articles · 2mo ago

    Npm supply-chain worm that steals publishing tokens and self-propagates

    Initial Disclosure

    The first malicious pgserve releases appeared on April 21, 2026 at 22:14 UTC, followed by additional infected versions later the same day. The earliest phase centered on compromised publishing tokens that let the worm republish tainted packages immediately.

    Show sources