Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros

May 30, 2026

AI-Generated npm Malware Leaks Its Own GitHub Token

May 29, 2026

GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension

May 29, 2026
Facebook X (Twitter) Instagram
Saturday, May 30
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»AI-Generated npm Malware Leaks Its Own GitHub Token
News

AI-Generated npm Malware Leaks Its Own GitHub Token

Team-CWDBy Team-CWDMay 29, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A malicious npm package has been caught leaking its own hardcoded GitHub token, a blunder that let researchers watch the operator’s data theft unfold from the inside.

The package, named mouse5212-super-formatter, was identified by OX Security according to new analysis from the firm’s research team. It functions as an infostealer, quietly reading files from a victim’s machine and uploading them to a repository the attacker controls.

The package had been downloaded 676 times and remained live on npm at the time of OX Security’s writeup on Wednesday, though it has since been removed.

Disguised as a Sync Utility

On the surface, the script presents itself as an internal “archive deployment sync” tool that checks a GitHub repository and records a network status snapshot.

In practice, OX Security found, the post-install code authenticates to GitHub, creates a repository if one does not exist, then recursively walks a local directory and uploads every file through the GitHub Contents API.

To blend in, the malware stores stolen files under a randomly named folder for each run and writes a fake “network connections” log so the activity resembles diagnostics rather than theft. Comments and commit messages were kept deliberately bland to avoid drawing attention.

The fatal flaw was a hardcoded fallback token left in the code. Because the malware carried the operator’s own GitHub credential, researchers could trace the exfiltration directly, observing around seven theft sessions in the attacker’s repository, most of which appeared to be the operator testing the tool.

A Sign of Sloppier Threats

OX Security framed the package as an example of malware generated with AI by an operator who did not grasp basic operational security.

The GitHub account behind it had been created only hours before the first upload and was deleted once the activity was exposed.

The episode points to a wider shift. As the effort needed to produce working malicious code falls, researchers expect a rise in low-quality, AI-assisted malware from less skilled actors, much of it imitating more capable groups.

The same dynamic was on display in VoidLink, a Linux malware strain that analysts concluded was largely AI-generated under the direction of a single person.

Read more on VoidLink: Linux Malware Was Built Using an AI Agent, Researchers Reveal

For defenders, the practical advice is unchanged by the attacker’s incompetence. OX Security urged anyone who installed the package to revoke their GitHub access tokens and treat any sensitive files in the affected directory as compromised.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleGitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension
Next Article 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros
Team-CWD
  • Website

Related Posts

News

9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros

May 30, 2026
News

GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension

May 29, 2026
News

Chinese Hackers Exploit Iran War to Target Maritime and Energy Firms

May 29, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

How to tell if a voice call is AI or not

February 23, 2026

What it is and how to protect yourself

January 8, 2026

Drowning in spam or scam emails lately? Here’s why

January 27, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.