LWA-2026-12199 MAL-2026-16246 ↗ confirmed malware

kartyk-github-token-pkg@1.0.4

Malicious code in kartyk-github-token-pkg (npm)

Analysis

Package kartyk-github-token-pkg@1.0.4 was published and then immediately unpublished. Its name is explicitly themed around GitHub token handling, consistent with a credential-harvesting package. No source content is available for analysis; the advisory is based on the package name and the publish-then-yank pattern.

analyzed by
Leitwacht
first seen
Sep 16, 2026, 11:31 PM
analyzed
Sep 16, 2026, 11:31 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.