Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

Npm Package Targets GitHub Repos

November 12, 2025
Reading Time: 3 mins read
in Alerts
WhatsApp Malware Hits Brazil Banks

Cybersecurity researchers have uncovered a malicious npm package named “@acitons/artifact” that employed typosquatting to mimic the legitimate “@actions/artifact” package, specifically aiming at repositories owned by GitHub. Researchers believed the intention was to execute a script during the build process of a GitHub-owned repository. This script was designed to steal tokens available within the build environment and then use those tokens to publish new, harmful artifacts, effectively impersonating GitHub.

The security company, Veracode, reported observing six versions of the malicious package, ranging from 4.0.12 to 4.0.17. These versions incorporated a post-install hook designed to download and execute malware. It is worth noting that the latest version currently available for download on npm is 4.0.10, which suggests that the threat actor, identified as “blakesdev,” subsequently removed the harmful versions.

The package was initially uploaded on October 29, 2025, and rapidly gained traction, accumulating 31,398 weekly downloads and a total of 47,405 downloads overall, according to npm-stat data. In addition to this main package, Veracode identified a second npm package, “8jfiesaf83,” that exhibited similar malicious functionality. Although this package is no longer available for download, it appears to have been downloaded 1,016 times before its removal.

Further investigation into one of the malicious versions revealed that the post-install script was configured to download a binary file named “harness” from a now-deleted GitHub account. This binary was an obfuscated shell script that included a time-based execution check, preventing it from running if the current time was after 2025-11-06 UTC. The script was also set to run a JavaScript file, “verify.js,” which checked for the presence of specific GITHUB_ variables associated with GitHub Actions workflows. Any collected data was then exfiltrated in an encrypted format to a text file hosted on the “app.github[.]dev” subdomain.

Veracode concluded that the malware was exclusively targeting repositories owned by the GitHub organization, making it a highly targeted attack against the company. However, in a subsequent statement, a GitHub spokesperson clarified that the identified packages were actually part of a “tightly controlled exercise” conducted by GitHub’s internal Red Team. The spokesperson emphasized that GitHub regularly tests its security posture through realistic Red Team simulations to ensure resilience, and stated that “at no point were GitHub systems or data at risk.”

Reference:

  • Npm Package Targeting GitHub Owned Repositories Identified As Red Team Exercise
Tags: Cyber AlertsCyber Alerts 2025CyberattackCybersecurityNovember 2025
ADVERTISEMENT

Related Posts

WhatsApp Malware Hits Brazil Banks

GootLoader Returns With Font Trick

November 12, 2025
WhatsApp Malware Hits Brazil Banks

WhatsApp Malware Hits Brazil Banks

November 12, 2025
Delayed Payloads Hit Nuget Packages

Glassworm Found In Three VS Code Addons

November 11, 2025
Delayed Payloads Hit Nuget Packages

Triofox Flaw Lets Hackers Install Remote

November 11, 2025
Delayed Payloads Hit Nuget Packages

Delayed Payloads Hit Nuget Packages

November 11, 2025
Lost iPhone Beware Fake Text Claims

Samsung Flaw Used To Install Landfall

November 10, 2025

Latest Alerts

Npm Package Targets GitHub Repos

GootLoader Returns With Font Trick

WhatsApp Malware Hits Brazil Banks

Glassworm Found In Three VS Code Addons

Triofox Flaw Lets Hackers Install Remote

Delayed Payloads Hit Nuget Packages

Subscribe to our newsletter

    Latest Incidents

    GlobalLogic Confirms Data Breach

    Hamburg Miniature Museum Hit By Hack

    Fraudster Jailed In £5.5Bn Bitcoin Scam

    Italian Adviser Targeted By Paragon Spyware

    Manassas Schools Close After Cyberattack

    Chinese Breach Exposes Cyber Weapons

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial