One Breached Maintainer Reaches npm, Go, and Actions
The blast radius is the maintainer identity, not just the poisoned package. Once attackers control a real publisher account and CI secrets, they can keep pushing malicious artifacts through the same trusted release paths across registries and workflows.
Socket links the new wave to malicious npm releases in the LeoPlatform and RStreams families, a compromised Verana Blockchain Go module, and GitHub Actions abuse. It also points to a suspected breached npm maintainer account, 'czirker', that let the campaign spread with little manual effort and steal more developer credentials.
That makes cleanup harder than removing one bad version. If the same publishing or workflow credentials are still valid, the campaign can keep generating new malicious releases across npm, Go, and GitHub Actions.