AI-Generated npm Malware Leaks Its Own GitHub Token
2026-05-29T08:52:16Z•21dd2288b7f2d14e145a0817871a041d73c63fd85ff9bf4406d1e4cbaf8d4d35
ai-generated-malwarebotnetcert-incredential-theftgithub-token-leakglasswormgrafana-breachinfostealerkali365malicious-extensionmini-shai-huludnpmoauth-token-theftpackage-impersonationpatchingphishingptrace-linuxseo-poisoningsupply-chaintanstackvs-code-extensionzero-day-disclosure
What happened
A cluster of high‑impact supply‑chain and credential‑theft incidents and trends: an AI‑generated npm infostealer accidentally leaked its own GitHub token; malicious VS Code extensions (Nx Console) and other supply‑chain attacks led to GitHub repository compromise and theft of Grafana source code (TanStack link); Mini Shai‑Hulud and other npm worms hit large package ecosystems; attackers are shifting from typosquatting to realistic package impersonation and SEO‑poisoning lures that distribute infostealers (targeting LLM sites and crypto developers). Phishing tooling and kits (Kali365) continue‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 21dd2288b7f2d14e145a0817871a041d73c63fd85ff9bf4406d1e4cbaf8d4d35
- Enrichment time
- 2026-05-29T08:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.