BREAKING
Fake npm Packages Mimic AI Vendors
0
packages
0
downloads
0
data types
How the attack chain worked
1
Typosquat AI package
↓
2
postinstall runs
↓
3
Harvest 11 data types
↓
4
Send to Cloud Run
Not your typical credential theft
Typical attacks
OLD
●
Steal passwords
●
Grab API tokens
This campaign
NEW
●
No credentials taken
●
Builds identity graph
●
Enables spear-phishing
0
B
initial
0
KB
refined
0
lines
Disable install scripts, scan deps
AI NEWS BLITZ
Malicious npm packages impersonated top AI vendors to harvest developer data.