@squawk/procedure-data 0.7.5
Obfuscated credential stealer with install hook dropper
Kubernetes token pivots through cloud metadatapreinstall setup.mjs bootstraps Bun runtime
SHA-25613707cd70c630426bfc7e2e6e3782249f7b6304a35181379ba60c06a9b3c4857
Also flagged by osv (MAL-2026-3452: Malicious code in @squawk/procedure-data (npm)) +3 more.