Executive Abstract
Examining malicious NPM and PyPI package publishing campaigns used to deliver stealthy infostealer payloads.

Detailed Threat Intelligence Breakdown

Threat actors have automated typosquatting package submissions to official package managers, embedding obfuscated post-install scripts that exfiltrate environment variables containing AWS, GCP, and GitHub tokens.

Key Findings & Strategic Observations

  • NPM & PyPI typosquatting automation
  • Environment variable token exfiltration