A Self-Propagating npm Worm Is Harvesting Developer API Keys Through postinstall Hooks. Here's the 15-Minute Audit Your CI/CD Pipeline Needs Today.
Three coordinated supply chain attacks hit npm, PyPI, and Docker Hub in a 48-hour window, stealing GitHub tokens, AWS credentials, SSH keys, and .env files via postinstall hooks and compromised official images. Solo operators running automated pipelines are the exact target profile.