Two Malicious npm Packages Aim to Steal Credentials and Other Secrets
DevOps - The Web's Largest Collection of DevOps Content [Unoffi…
March 23, 2026
Bad actors took over a npm maintainer account and have published two malicious packages designed to steal credentials, API keys, and other secrets from the computers of victims who download them from the repository. Analysts with Sonatype’s Security Research Team wrote in a report that the two packages – sbx-mask and touch-adv – likely are […]
Discussion in the ATmosphere