Package Registries Target Developer Secrets
Coverage from BleepingComputer, Security Boulevard, and others

Attackers are repeatedly compromising or impersonating packages on npm and PyPI to steal developer credentials, cloud secrets, CI/CD tokens, and cryptocurrency wallet data.
Several campaigns use trusted publishing accounts, malicious installation hooks, typosquatted dependencies, or self-propagation to reach additional packages and repositories. The activity affects enterprise tooling, AI software, payment integrations, and widely downloaded development ecosystems, while attribution remains mixed between TeamPCP-linked malware, other threat actors using leaked code, and a Microsoft-attributed North Korean operation.
The story now emphasizes a broader set of credential-theft techniques and a wider operational footprint, including enterprise tooling, AI software, payment integrations, and common JavaScript dependencies. It also adds more specific campaign details, especially the Red Hat package compromise scale and the use of CI runner memory scanning and GitHub-based dead drops.
The story broadens from npm-only credential theft into a wider cross-ecosystem campaign that now includes PyPI and self-propagating malware behavior. Attribution also sharpens, with Microsoft tying the Mastra campaign to North Korean Sapphire Sleet and researchers linking some activity to leaked Shai-Hulud malware.
