Regtech SlowMist Analyzes Malicious Code Stealing Sensitive Keys, Private Information

Date:

Share post:


Regtech firm SlowMist noted that recently, the NPM ecosystem has experienced another large-scale package poisoning incident. For context, the so-called NPM ecosystem is the vast, interconnected system of the Node Package Manager (npm), which includes the “online registry of software packages and the command-line interface (CLI) developers use to manage them.”

It allows devs to discover, install, and share reusable code modules, “forming the foundation for a large portion of JavaScript and TypeScript development by automating dependency management and code sharing.”

This ecosystem’s strength is also its “vulnerability, as a compromise in one package can have a widespread impact on many other projects.”

As noted by SlowMist, this event is highly related to the Shai-Hulud attack that occurred in Sept 2025. The malicious code embedded in the compromised NPM packages was reportedly “designed to steal sensitive information, including developer keys, API keys, and environment variables.”

Using the stolen credentials, the attacker had reportedly created “public repositories and uploaded the exfiltrated data.”

SlowMist’s independently developed Web3 threat-intelligence and real-time security monitoring platform, MistEye, responded “immediately and swiftly pushed relevant threat intelligence to provide critical security protection for our clients.”

SlowMist went on to describe a credential theft:

  • AWS: The malicious script implements two functions — runSecrets() and listAndRetrieveAllSecrets(). The runSecrets() function iterates through all discoverable cloud access credentials and all possible regions to maximize the scanning scope.
  • The listAndRetrieveAllSecrets() function then performs “deep enumeration” within the specified credentials and region, listing all Secrets and retrieving their most recent plaintext values.
  • By combining these two functions, the attacker is able to extract all accessible SecretString and SecretBinary values from the victim’s AWS account in a single sweep.

In the process of stealing sensitive information, the malicious “script also abuses legitimate security tools against the victim.”

As noted in the report:

The malicious script implements an updatePackage() function that is used to perform NPM supply-chain propagation. Using the stolen NPM token, it first downloads the source code of legitimate NPM packages for which the victim holds publish permissions. It then modifies the package.json file by injecting a malicious preinstall script command into the scripts field, and inserts the malicious payload into the package. The package version number is automatically incremented by one to trigger users’ automatic updates, after which the compromised package containing the malicious script is published to the official NPM registry.”

The report from SlowMist concluded:

“This NPM repository poisoning incident combines worm‑like propagation with long‑term persistence via self‑hosted runners, and further leverages TruffleHog as part of the attack chain. The SlowMist security team recommends that developers adopt strict dependency version‑locking strategies when building and releasing new iterations. If a dependency requires security or functional updates, it should be upgraded only through an internal, rigorous security review process, and the locked versions should be updated accordingly to avoid introducing new risks through blind updates.”



LEAVE A REPLY

Please enter your comment!
Please enter your name here

Related articles

BNPL Fintech Klarna Enhances Nordics Anti-Fraud Toolkit With Live Call Verification Feature

Klarna (NYSE: KLAR) has added a new layer of protection for customers in the Nordic region, rolling...

UK inflation accelerates to 3.1% in August on sharp rise in fuel prices

UK inflation accelerates to 3.1% in August on sharp rise in fuel prices

Pierre Poilievre joins Ron Butler for housing, homeownership discussion

The Conservative leader joined mortgage broker Ron Butler for a wide-ranging discussion on housing affordability, development costs...

𝐒𝐡𝐚𝐩𝐞 𝐘𝐨𝐮𝐫 𝐟𝐮𝐭𝐮𝐫𝐞 𝐰𝐢𝐭𝐡 𝐚 𝐁𝐚𝐜𝐡𝐞𝐥𝐨𝐫 𝐨𝐟 𝐌𝐚𝐧𝐚𝐠𝐞𝐦𝐞𝐧𝐭 (𝐇𝐨𝐧𝐨𝐮𝐫𝐬) 𝐢𝐧 𝐁𝐮𝐬𝐢𝐧𝐞𝐬𝐬 𝐀𝐝𝐦𝐢𝐧𝐢𝐬𝐭𝐫𝐚𝐭𝐢𝐨𝐧

𝐉𝐨𝐢𝐧 𝐂𝐈𝐍𝐄𝐂, 𝐚 𝐩𝐫𝐞𝐦𝐢𝐞𝐫 𝐚𝐜𝐚𝐝𝐞𝐦𝐢𝐜 𝐢𝐧𝐬𝐭𝐢𝐭𝐮𝐭𝐢𝐨𝐧 𝐢𝐧 𝐒𝐫𝐢 𝐋𝐚𝐧𝐤𝐚, 𝐝𝐞𝐝𝐢𝐜𝐚𝐭𝐞𝐝 𝐭𝐨 𝐜𝐮𝐥𝐭𝐢𝐯𝐚𝐭𝐢𝐧𝐠 𝐭𝐨𝐩-𝐭𝐢𝐞𝐫 𝐭𝐚𝐥𝐞𝐧𝐭 𝐟𝐨𝐫 𝐭𝐡𝐞 𝐞𝐯𝐨𝐥𝐯𝐢𝐧𝐠 𝐧𝐞𝐞𝐝𝐬...