AI-Generated npm Package Leaks Its Own GitHub Token, Exposing Malware Operator
By
Alessandro Mascellino
Crispy enough to crunch, soft enough to enjoy. A good bake.
Summary
A malicious npm package named mouse5212-super-formatter, identified by OX Security, was caught leaking its own hardcoded GitHub token. This blunder allowed researchers to observe the attacker's data theft operations from the inside. The package functioned as an infostealer, reading files from victims' machines and uploading them to a repository controlled by the attacker. It had been downloaded 676 times before being removed from npm. The malware is believed to be AI-generated, and the leaked token exposed the operator's identity and activities.
Key quotes
· 4 pulledA malicious npm package has been caught leaking its own hardcoded GitHub token, a blunder that let researchers watch the operator's data theft unfold from the inside.
The package, named mouse5212-super-formatter, was identified by OX Security according to new analysis from the firm's research team.
It functions as an infostealer, quietly reading files from a victim's machine and uploading them to a repository the attacker controls.
The package had been downloaded 676 times and remained live on npm at the time of OX Security's writeup on Wednesday, though it has since been removed.
You might also wanna read
317 npm Packages Compromised in Mini Shai-Hulud Supply Chain Attack
A major npm supply chain attack occurred on May 19, 2026, when the npm account of maintainer "atool" was compromised. The attacker published
Major NPM Supply Chain Attack: @ctrl/tinycolor and 40+ Packages Compromised with Self-Propagating Malware
A sophisticated supply chain attack has compromised the popular @ctrl/tinycolor NPM package (with over 2 million weekly downloads) along wit
GitHub Issue Prompt Injection Leads to 4,000 Developer Machines Compromised via Malicious npm Package
A sophisticated supply chain attack compromised approximately 4,000 developer machines through a GitHub issue title prompt injection. The at
Security Alert: Malicious Nx Packages Published to npm Containing Credential-Stealing Code
Malicious versions of the Nx package and several supporting plugins were published to npm, containing code that scans file systems, collects
GitLab Identifies Large-Scale npm Supply Chain Attack with Destructive Malware
GitLab's security researchers have uncovered a large-scale supply chain attack in the npm ecosystem involving a destructive malware variant
Nx Build Kit Security Breach: Malware Steals Wallets and Credentials via GitHub Repositories
A security breach has been discovered in the popular Nx build kit where malicious post-install commands create unauthorized repositories nam
