BREAKING
Fake npm Packages Mimic AI Vendors
0
packages
0
downloads
0
data types
How the attack chain worked
1Typosquat AI package
2postinstall runs
3Harvest 11 data types
4Send to Cloud Run
Not your typical credential theft
Typical attacksOLD
Steal passwords
Grab API tokens
This campaignNEW
No credentials taken
Builds identity graph
Enables spear-phishing
0B
initial
0KB
refined
0
lines
Disable install scripts, scan deps
AI NEWS BLITZ
Malicious npm packages impersonated top AI vendors to harvest developer data.