Researchers Detect Malicious npm Package Targeting GitHub-Owned Repositories

Cybersecurity researchers have found a harmful npm package called “@acitons/artifact” that typosquats the legitimate “@actions/artifact” package, aiming to target repositories owned by GitHub.

According to an analysis by Veracode, it appears the intention was for this script to run during a build of a repository owned by GitHub, exfiltrate the tokens present in the build environment, and use those tokens to publish new malicious artifacts under GitHub’s name.

The cybersecurity firm reported that it noted six iterations of the package, ranging from 4.0.12 to 4.0.17, which included a post-install hook for downloading and executing malware. However, the most recent version you can download from npm is 4.0.10, which suggests that the malicious actor responsible for the package, blakesdev, has eliminated all problematic versions.

After being uploaded for the first time on October 29, 2025, the package has accumulated a total of 31,398 downloads on a weekly basis. According to npm-stat data it has been downloaded a total read more about Researchers Detect Malicious npm Package Targeting GitHub-Owned Repositories.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *