Last Update: 09/22/2026 at 11:34 PM EST

Package Registries Target Developer Secrets

Coverage from BleepingComputer, Security Boulevard, and others

Package Registries Target Developer Secrets topic image

Attackers are repeatedly compromising or impersonating packages on npm and PyPI to steal developer credentials, cloud secrets, CI/CD tokens, and cryptocurrency wallet data.

Several campaigns use trusted publishing accounts, malicious installation hooks, typosquatted dependencies, or self-propagation to reach additional packages and repositories. The activity affects enterprise tooling, AI software, payment integrations, and widely downloaded development ecosystems, while attribution remains mixed between TeamPCP-linked malware, other threat actors using leaked code, and a Microsoft-attributed North Korean operation.

Looking Back
115 Day Timeline
Mar 23Apr 13May 4Jun 1Jun 22Jul 13
History
07/25/2026

The story now emphasizes a broader set of credential-theft techniques and a wider operational footprint, including enterprise tooling, AI software, payment integrations, and common JavaScript dependencies. It also adds more specific campaign details, especially the Red Hat package compromise scale and the use of CI runner memory scanning and GitHub-based dead drops.

07/24/2026

The story broadens from npm-only credential theft into a wider cross-ecosystem campaign that now includes PyPI and self-propagating malware behavior. Attribution also sharpens, with Microsoft tying the Mastra campaign to North Korean Sapphire Sleet and researchers linking some activity to leaked Shai-Hulud malware.

All Articles17 articles
Additional17 articles · CI Score below 45
BleepingComputer / Bill Toulas
7/15/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Bill Toulas
7/8/2026 • Cybersecurity Tech (Privacy-Relevant) • General
BleepingComputer / Lawrence Abrams
6/20/2026 • Cybersecurity Tech (Privacy-Relevant) • General
BleepingComputer / Lawrence Abrams
6/1/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Bill Toulas
5/18/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Lawrence Abrams
4/29/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Bill Toulas
4/22/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Bill Toulas
3/30/2026 • Cybersecurity (Privacy-Relevant) • General
Security Boulevard / Ron Popov
3/30/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Bill Toulas
7/13/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Bill Toulas
6/9/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Lawrence Abrams
4/13/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Lawrence Abrams
4/3/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Bill Toulas
3/23/2026 • Cybersecurity (Privacy-Relevant) • General
Securityboulevard / Ron Popov
3/30/2026 • Cybersecurity (Privacy-Relevant) • General
Security Boulevard / Ron Popov
3/30/2026 • Cybersecurity (Privacy-Relevant) • General
Security Boulevard / Ron Popov
3/30/2026 • Cybersecurity (Privacy-Relevant) • General