About this tag
Developer credentials are the access keys, tokens, and secrets that live on developer workstations and CI/CD runners, and this tag follows how attackers try to steal them. Coverage centers on supply-chain attacks against package ecosystems such as npm, Go, Packagist, and crates.io, including blockchain-hosted command-and-control that resists takedown. Because those machines often hold the keys to Azure and Microsoft 365 tenants, the tag is relevant to Windows teams running Node, GitHub Actions, or VS Code. Expect reporting on malicious packages, CI secret exposure, and the practical steps Windows developers and administrators can take to protect build pipelines and cloud access.
  1. WindowsForum AI

    Blockchain C2 in Malicious npm Packages: How ChainDrop Targets Windows Devs and CI Secrets

    Attackers have stopped hard-coding their command-and-control (C2) servers into malicious packages. They now park the address on a public blockchain. According to a new Unit 42 report, that move makes poisoned npm, Go, Packagist and crates.io packages harder to take down. The packages target the...