Threats Tagged 'github compromise'
View all threats tagged with 'github compromise'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'github compromise'
Click on any threat for detailed analysis and mitigation recommendations
Attackers compromised a GitHub maintainer account controlling keyv, cacheable, flat-cache, and file-entry-cache Node.js packages that collectively receive over a billion downloads monthly. Malicious code was pushed directly to the main branch and automatically published to npm with valid signatures. A hidden preinstall script downloads a Bun runtime to execute an obfuscated payload that harvests npm, GitHub, AWS, Kubernetes, and Vault credentials, scans for SSH keys and environment files, and exfiltrates data to attacker-controlled GitHub repositories and Ethereum smart contracts. The worm then uses stolen npm tokens to infect additional packages autonomously. This self-propagating attack, tracked as ChainDrop, belongs to the Shai Hulud family responsible for previous campaigns targeting TanStack, Mistral AI, and OpenSearch packages in May 2026. Join the discussion | AlienVault OTX General | 08/05/2026, 08:28:38 UTC Added: 08/05/2026, 08:56:25 UTC |
Multiple npm packages in the keyv/cacheable ecosystem were compromised after attackers gained control of a GitHub maintainer account. Beginning at 9:00 UTC on August 4, 2026, the attacker introduced IDE persistence mechanisms and published malicious versions that propagated to over 400 distinct packages. The payload is a descendant of the 'Mini' Shai-Hulud malware family, sharing similarities with TeamPCP and antv campaigns. It targets sensitive data including cloud credentials, infrastructure secrets, developer credentials, AI configuration files, and cryptocurrency wallets. The malware uniquely retrieves command-and-control domains from an Ethereum smart contract rather than embedding them, allowing infrastructure updates without modifying the payload. Data is exfiltrated through GitHub repositories created under compromised identities. The campaign demonstrates sophisticated supply chain attack techniques targeting developer environments and CI/CD pipelines. Join the discussion | AlienVault OTX General | 08/04/2026, 18:15:36 UTC Added: 08/05/2026, 09:26:29 UTC |
Showing 1 to 2 of 2 results