All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

AI-Generated npm Package Leaks Its Own GitHub Token, Exposing Malware Operator

By

Alessandro Mascellino

2d ago· 3 min readenNews

Summary

A malicious npm package named mouse5212-super-formatter, identified by OX Security, was caught leaking its own hardcoded GitHub token. This blunder allowed researchers to observe the attacker's data theft operations from the inside. The package functioned as an infostealer, reading files from victims' machines and uploading them to a repository controlled by the attacker. It had been downloaded 676 times before being removed from npm. The malware is believed to be AI-generated, and the leaked token exposed the operator's identity and activities.

Key quotes

· 4 pulled
A malicious npm package has been caught leaking its own hardcoded GitHub token, a blunder that let researchers watch the operator's data theft unfold from the inside.
The package, named mouse5212-super-formatter, was identified by OX Security according to new analysis from the firm's research team.
It functions as an infostealer, quietly reading files from a victim's machine and uploading them to a repository the attacker controls.
The package had been downloaded 676 times and remained live on npm at the time of OX Security's writeup on Wednesday, though it has since been removed.
Snippet from the RSS feed
Sloppy AI-generated npm infostealer leaked its own GitHub token, exposing the operator

You might also wanna read