
11/24/2025 · Michael Henriksen
What this post added
This post details the discovery and technical analysis of a widespread npm supply chain attack involving a destructive malware variant. It outlines the malware's multi-stage infection vector, credential harvesting techniques (GitHub, npm, cloud), data exfiltration methods using attacker-controlled GitHub repositories, and its worm-like propagation mechanism within the npm ecosystem. A critical component is the 'dead man's switch' payload that triggers data destruction if the malware loses access to its infrastructure. The post also provides indicators of compromise and explains how GitLab's Dependency Scanning can help detect this campaign.