kartyk-github-token-pkg@1.0.4
Malicious code in kartyk-github-token-pkg (npm)
Analysis
Package kartyk-github-token-pkg@1.0.4 was published and then immediately unpublished. Its name is explicitly themed around GitHub token handling, consistent with a credential-harvesting package. No source content is available for analysis; the advisory is based on the package name and the publish-then-yank pattern.
- analyzed by
- Leitwacht
- first seen
- Sep 16, 2026, 11:31 PM
- analyzed
- Sep 16, 2026, 11:31 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.