Five npm malicious packages caught exfiltrating CI/CD and local machine secrets

Today we are disclosing a significant supply-chain compromise in the npm ecosystem. Five npm packages published by the user npmhell, all of which have now been removed from the registry, have been downloaded multiple times (200+ downloads each) in the last 30 days. These packages were built with malicious install-time code designed to harvest developer […]