216.73.216.145

[email protected] Harvesting Github Credentials

· Published 24/07/2026 03:19

Export JSON

Essential information

Published
24/07/2026 03:19
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
credential-theft github intercom npm shai-hulud supply-chain typescript worm
Related entities
1 indicators, 1 observables, 1 intrusion sets (apt)

Description

The TypeScript Library version 7.0.4 has been compromised with malicious code that harvests credentials. Upon installation, the package executes a preinstall hook that downloads the Bun runtime, then runs a payload to extract credentials using the gh auth token command. The attack employs sophisticated C2 communication by querying 's commit search API for specific strings embedded in public repositories, effectively using legitimate services to evade detection. The attack patterns mirror previous compromises, which exhibit -like behavior by automatically using stolen credentials to infect additional packages. With 361,510 weekly downloads, this compromise poses significant risk for a widespread infection wave similar to November 2025 when over 1,000 packages were affected.

External references