Hostile dependency contains malware
Fallout in github, Aug 10 – Aug 16
What we caught this week while monitoring over 163,411,591 artifacts across 47 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.
SUNDAY
Sun Aug 16 · 4 catches · 0 waves · 3 singlesMalicious VS Code task executes obfuscated dropper
delivery/blockchaininstall-hook/tasks
SATURDAY
Sat Aug 15 · 7 catches · 0 waves · 3 singlesNPM install hook exfiltrates environment
credential-theft/envdepends on hostile npm: @semantic-release/npm v13.1.5
Embedded malicious postinstall script
dropper/download-executedropper/pipe-execute
FRIDAY
Fri Aug 14 · 3 catches · 0 waves · 3 singlesNPM install hook exfiltrates environment
credential-theft/env
Embedded malicious HTTP desync probe
obfuscated Lua dropper in archive
code-metrics/structureexecution/lua-sidecar
THURSDAY
Thu Aug 13 · 2 catches · 0 waves · 2 singlesmalicious npm dependency htmlescape
Embedded obfuscated Lua dropper
masquerade/wrapperhidden-payload/exec
WEDNESDAY
Wed Aug 12 · 9 catches · 0 waves · 3 singlesTCC manipulation, credential theft, agent hooks
automation/agenttcc-manipulation/db
Detached worker runs unrestricted Claude agent
automation/agentcleanup/remove
TCC manipulation, credential theft, AI agent targeting
automation/agentbrowser/firefox
MONDAY
Mon Aug 10 · 1 catch · 0 waves · 1 singleNPM install hook exfiltrates environment
credential-theft/envlibrary/source
O objectives H behaviours Md metadata · a group subscript counts categories, an atom subscript subcategories