Critical npm malware steals crypto and cloud secrets from developers
Security researchers have discovered a critical new malware campaign in the npm ecosystem targeting developers and their valuable credentials. The attack, linked to the compromised npm account ‘czirker’, affects 23 packages and has already left 408 infected GitHub repositories filled with stolen login credentials at the time of discovery.
How the attack works
The campaign is known as ‘Alright Lets See If This Works’ and is a variant of the previously known Shai-Hulud, Miasma and Hades malware families. The attackers abuse a preconfigured binding.gyp file that automatically executes malicious code as soon as a developer runs an npm install. This means that simply installing an infected package is enough to become a victim.
One of the affected packages is leo-logger, which is downloaded approximately 3,140 times per week via npm. The malware targets the theft of GitHub tokens, npm tokens and cloud credentials from platforms such as AWS, GCP and Azure. Additionally, it exfiltrates local environment data, abuses GitHub workflows and spreads further through the npm supply chain.
What developers should do now
Security teams are strongly advised to take immediate action. Check lockfiles and package histories for infected versions and remove or downgrade affected packages as soon as possible. It is also essential to rotate all secrets, including npm tokens, GitHub tokens, cloud credentials, CI/CD keys and application secrets.
SlowMist also recommends enabling two-factor authentication (2FA) on all accounts involved. The affected packages include, among others, npm:leo-sdk, npm:leo-cli, npm:leo-auth and dozens of other leo-connector packages. The situation has been classified as ‘critical’ and is being actively monitored. The latest updates can be followed at https://enterprise.misteye.io/threat-intelligence/SM-2026-733101
Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.
Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.