ThreatCluster

Malicious npm Package with 206K Downloads Exploits GitHub Token Theft

First seen 13 Nov 2025, 17:30 UTC GbhackersCyberpress 24

Article Content

Browse articles
ThreatCluster

A malicious npm package, downloaded over 206,000 times, has been identified as exploiting vulnerabilities to steal sensitive tokens from GitHub repositories. This incident affects developers who unknowingly installed the compromised package, potentially leading to unauthorized access to their GitHub accounts and associated resources.