Xanadu hit by network compromise
Incident
Summary
Hide ▲
Show ▼
Xanadu confirmed a GitHub account breach that enabled a poisoned mrmustard 0.7.4 release, putting SSH private keys, AWS credentials, and Kubernetes configurations at risk. The rogue package turned routine imports into credential theft and sent data to metrics.femboy[.]energy. Attackers appear to have probed the project’s self-hosted CI runners to recover publishing secrets before pushing the malicious version. The compromise raises follow-on access risk for a research and HPC environment that relies on the library.
Related Happenings
Mastra @mastra/* npm packages hit by network compromise
Incident
H score47
First: 17.06.2026 10:38
Last: 17.06.2026 10:38
Sources 1
About this happening:
Mastra @mastra/* npm packages were compromised in a software supply chain attack that spread through the namespace on 2026-06-17. Microsoft now attributes the acti...
Mastra @mastra/* npm packages hit by network compromise
IncidentAbout this happening: Mastra @mastra/* npm packages were compromised in a software supply chain attack that spread through the namespace on 2026-06-17. Microsoft now attributes the acti...
Latest development: 20.06.2026 17:09
Microsoft attributed the Mastra AI supply chain attack to Sapphire Sleet, also known as BlueNoroff, and said the attackers compromised the npm maintainer account ehindero, which had publishing privileges across the Mastra package environment. The June 19 update said more than 140 packages in the @mastra scope were modified to inject easy-day-js.
IronWorm npm supply-chain infection and self-propagation
Malware Activity
H score15
First: 04.06.2026 18:25
Last: 04.06.2026 18:25
Sources 1
About this happening:
IronWorm is a Rust infostealer in a npm supply-chain activity that hides behind an eBPF kernel rootkit, communicates over Tor, and targets 86 environment var...
IronWorm npm supply-chain infection and self-propagation
Malware ActivityAbout this happening: IronWorm is a Rust infostealer in a npm supply-chain activity that hides behind an eBPF kernel rootkit, communicates over Tor, and targets 86 environment var...
JINX-0164 cryptocurrency recruitment-lure campaign
Campaign
H score39
First: 28.05.2026 10:54
Last: 28.05.2026 10:54
Sources 1
About this happening:
A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...
JINX-0164 cryptocurrency recruitment-lure campaign
CampaignAbout this happening: A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...
AUDIOFIX and MiniRAT macOS malware activity
Malware Activity
H score34
First: 28.05.2026 10:54
Last: 28.05.2026 10:54
Sources 1
About this happening:
The AUDIOFIX and MiniRAT malware activity is targeting cryptocurrency firms and developer infrastructure on macOS with LinkedIn recruiter lures, a fake mee...
AUDIOFIX and MiniRAT macOS malware activity
Malware ActivityAbout this happening: The AUDIOFIX and MiniRAT malware activity is targeting cryptocurrency firms and developer infrastructure on macOS with LinkedIn recruiter lures, a fake mee...
TanStack hit by network compromise
Incident
H score29
First: 12.05.2026 17:45
Last: 12.05.2026 17:45
Sources 1
About this happening:
TanStack was hit by a package compromise on May 11, 2026, when attackers published 84 malicious versions across 42 @tanstack/* packages and abused the release...
TanStack hit by network compromise
IncidentAbout this happening: TanStack was hit by a package compromise on May 11, 2026, when attackers published 84 malicious versions across 42 @tanstack/* packages and abused the release...
Latest development: 21.05.2026 11:00
On May 17, 2026, Grafana Labs said an unauthorized attacker had downloaded its codebase after accessing the firm's GitHub environment, and the company later said additional internal operational information and business contact names and email addresses were taken from its GitHub repositories; Grafana Labs said there was no indication that customer production systems or the Grafana Cloud platform were compromised.
Timeline
-
03.08.2026 21:43 2 articles · 1h ago
Xanadu maintainer account breach pushes poisoned mrmustard 0.7.4
Initial DisclosureUnknown threat actors compromised Xanadu's primary maintainer GitHub account and pushed a poisoned mrmustard 0.7.4 release that runs an information stealer on package import. The malicious package targets research and HPC environments by harvesting SSH private keys, AWS credentials, and Kubernetes configurations and exfiltrating them to metrics.femboy[.]energy.
Show sources
- 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users — thehackernews.com — 03.08.2026 21:43
- 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users — thehackernews.com — 03.08.2026 21:43