External Publication
Visit Post

Two Malicious npm Packages Aim to Steal Credentials and Other Secrets

DevOps - The Web's Largest Collection of DevOps Content [Unoffi… March 23, 2026
Source
Bad actors took over a npm maintainer account and have published two malicious packages designed to steal credentials, API keys, and other secrets from the computers of victims who download them from the repository. Analysts with Sonatype’s Security Research Team wrote in a report that the two packages – sbx-mask and touch-adv – likely are […]

Discussion in the ATmosphere

Loading comments...