Security researchers uncovered a sophisticated supply chain attack in which malicious code was injected into a popular open-source development library downloaded millions of times per week.

The compromised versions harvested environment variables, cloud access keys and CI/CD secrets from build environments, exfiltrating them to attacker-controlled infrastructure disguised as a telemetry endpoint.

The attacker gained publishing access by compromising a maintainer's account through a phishing email that mimicked the package registry's security notifications. The malicious versions were live for eleven days before detection.

Registry operators have revoked the affected releases and introduced mandatory hardware-key authentication for maintainers of high-download packages. Organizations are urged to rotate any credentials present in build systems during the exposure window.