Malicious Packages Turn Dev Installs Into Cloud Breaches

Qualys Blog · High sophistication
Last updated September 28, 2026

The article describes real supply-chain campaigns where attackers hid credential-stealing code inside trusted open-source packages and developer tools. When a developer or CI system installed the package, the malware ran immediately, stole cloud and pipeline credentials, and enabled unauthorized cloud activity using valid access. The key message is that removing the bad package is not enough, teams must rotate exposed credentials and investigate what those credentials could access in the cloud.

Key findings

  • Install-time scripts in malicious packages can steal secrets before any application runs.
  • Stolen developer/CI credentials can be used to access cloud resources with valid accounts, making the cloud the true blast radius.
  • Campaigns described include compromised npm ecosystems, malicious Ruby gems and Go modules, and tampered CI/CD tooling.
  • Containment requires credential revocation/rotation and reviewing cloud audit activity, not just removing the package.

Who’s being targeted

  • Commonly targeted roles: Developers, DevOps / CI-CD Engineers, Application Security, Cloud Security, Engineering Leadership.
  • Affected industries: Software development, Technology / SaaS, Cloud services, DevOps / CI-CD operations, Open-source ecosystems.
  • Attack channels: github, website.
  • Impersonated: A trusted npm package in the @ctrl / @antv ecosystem, Developer utility packages (Ruby gems / Go modules) published from “BufferZoneCorp”, Trusted developer/security tooling used in CI/CD.

Awareness takeaways

  • Treat dependency installs as a high-risk action because malware can run before the app ever starts.
  • If a build runner or developer machine ran an untrusted package, rotate/revoke all credentials it could access and review cloud logs for misuse.
  • Reduce the blast radius by limiting CI/CD secrets and using short-lived cloud credentials wherever possible.
  • Watch for cloud pivots after credential theft by monitoring audit logs and alerting on unusual API calls made with valid credentials.

Red flags to watch for

  • Unexpected network activity during dependency install
  • Install scripts running even when the install is canceled
  • New or unexpected GitHub repository activity tied to the developer account
  • Package publisher/account is unfamiliar or newly created
  • Install changes system settings (PATH/GOPROXY) or writes to SSH authorized_keys
  • Checksum verification disabled or warnings suppressed during install
  • Unexpected force-pushes or tag changes in repositories
  • Secrets exposure despite GitHub masking (suggesting memory scraping)
  • Unexplained cloud API calls made with legitimate credentials shortly after pipeline runs
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You run npm install, it fails, you shrug it off. But that failed install might’ve just logged into your cloud. In the Shai-Hulud campaign, a poisoned @ctrl/tinycolor package ran a preinstall hook that stole cloud and CI secrets, then pushed them to a public GitHub repo created under the victim’s own account. Another campaign used a GitHub account called BufferZoneCorp to ship fake Ruby and Go utilities. During install they grabbed env vars, rewrote GOPROXY, and even added an SSH key to ~/.ssh/authorized_keys on build hosts. If any untrusted package ever ran on your dev box or CI, don’t just uninstall it, immediately rotate those credentials and review your cloud audit logs for weird API calls.

Categories

Similar attacks

Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
GitHub Issues Triggered CI Secret Leaks in AI Agents

GitHub Issues Triggered CI Secret Leaks in AI Agents

Security researchers showed that simply opening a GitHub issue could trigger default CI workflows in popular coding-agent projects and lead to code execution or secret exposure. The weaknesses were not in the AI models themselves, but in the surrounding automation (“harness”) that allowed untrusted…

August 7, 2026
GitHub Issue Trick Turns AI Coders Against Repos

GitHub Issue Trick Turns AI Coders Against Repos

Researchers showed that a single public GitHub issue (from someone with no repo access) could steer popular AI coding agents into running dangerous commands, exposing tokens, and changing repositories. The risk comes from AI agents reading untrusted issue/PR text while also having access to…

August 6, 2026
Poisoned AI Agent Files Turn Dev Tools Into Spies

Poisoned AI Agent Files Turn Dev Tools Into Spies

Researchers found real GitHub repositories containing poisoned AI-agent instruction/config files (like CLAUDE.md and .cursorrules) that silently tell coding assistants to steal prompts, environment variables, and credentials. The malicious instructions can trigger hidden commands (for example, curl…

August 4, 2026
Stolen API Key Ran Up $600K AI Usage at METR

Stolen API Key Ran Up $600K AI Usage at METR

AI research non-profit METR disclosed two real security incidents. In one, attackers got access to an exposed system and used an AI agent to reveal an API key, then burned through about $600,000 in AI credits over weeks. In a separate incident, METR observed systematic probing of its public…

September 2, 2026
800 Typosquat npm Packages Push RAT via README

800 Typosquat npm Packages Push RAT via README

Researchers found nearly 800 malicious npm packages that trick developers into installing them through typo-squatted package names and believable documentation. Instead of auto-running on install, the packages rely on the developer following README instructions to load the module, which then…

August 7, 2026