🚨 NPM Malware-slop Alert!🚨
We detected and reported a malware-slop package to npm - the malware uses it's OWN PRIVATE GitHub token, which is EMBEDDED INSIDE the malware itself - to read sensitive information and upload it to the threat actor's GitHub repository.
The malware is still live on npm -
The threat actor's GitHub page was opened 5h ago -
Detailed report will be published tomorrow.