Hostile 100% javascript Download

flat-cache 6.1.24

obfuscated credential stealer in preinstall

“A simple key/value storage using files to persist the data”

Obfuscated JavaScript targets AWS and GitHub runner credentialsSelf-defending string-array feeds Function loader
SHA-2566ee1bbd62f50eda62215a4c04b018ee10d46c2d542a5983b6030f3ff27e419d1

Also flagged by https://www.aikido.dev/blog/rss.xml (The dark figure of supply chain detection), osv (MAL-2026-11971: Malicious code in flat-cache (npm)) +5 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.