RoshniNaveenaS's account hit by network compromise
Incident
Summary
Hide ▲
Show ▼
The RoshniNaveenaS account was compromised, enabling attackers to publish malicious @cap-js releases without provenance and putting downstream npm consumers at risk. The abuse used a modified workflow on a non-main branch and an extracted npm OIDC token to push poisoned packages through trusted publishing infrastructure. The incident matters because legitimate package-release mechanisms were turned into a supply-chain delivery path.
Related Happenings
AsyncAPI repositories and npm publishing workflow hit by network compromise
Incident
H score27
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
AsyncAPI repositories and npm publishing workflow hit by network compromise
IncidentAbout this happening: The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
Jscrambler hit by network compromise
Incident
H score15
First: 13.07.2026 22:44
Last: 13.07.2026 22:44
Sources 1
About this happening:
The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...
Jscrambler hit by network compromise
IncidentAbout this happening: The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...
@Injectivelabs/[email protected] wallet-stealing package
Malware Activity
H score30
First: 10.07.2026 20:29
Last: 10.07.2026 20:29
Sources 1
About this happening:
The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...
@Injectivelabs/[email protected] wallet-stealing package
Malware ActivityAbout this happening: The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...
Injective Labs SDK project GitHub repository hit by network compromise
Incident
H score21
First: 09.07.2026 23:10
Last: 09.07.2026 23:10
Sources 1
About this happening:
The Injective Labs SDK project suffered a GitHub repository compromise that let attackers publish a malicious @injectivelabs/sdk-ts v1.20.21 package, putting developer...
Injective Labs SDK project GitHub repository hit by network compromise
IncidentAbout this happening: The Injective Labs SDK project suffered a GitHub repository compromise that let attackers publish a malicious @injectivelabs/sdk-ts v1.20.21 package, putting developer...
GitHub npm version 12 hardens installs and token management
Security Tool/Service
H score11
First: 09.07.2026 19:49
Last: 09.07.2026 19:49
Sources 1
About this happening:
GitHub released npm version 12, making install-time scripts opt-in by default and tightening package publishing controls to reduce supply-chain risk. The update al...
GitHub npm version 12 hardens installs and token management
Security Tool/ServiceAbout this happening: GitHub released npm version 12, making install-time scripts opt-in by default and tightening package publishing controls to reduce supply-chain risk. The update al...
Timeline
-
29.04.2026 19:26 2 articles · 2mo ago
RoshniNaveenaS's account hit by network compromise
Initial DisclosureOn April 29, 2026, attackers compromised the RoshniNaveenaS account for the @cap-js packages and used a modified workflow to obtain publishing capability. The first phase ended when the malicious packages were published without provenance through an extracted npm OIDC token.
Show sources
- SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack — thehackernews.com — 29.04.2026 19:26
- SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack — thehackernews.com — 29.04.2026 19:26