Cremit
/incidentsfield log
CatchesCampaignsExfilPatternsLLMIncidentsMethodology
↺rss↗cremit.io

incidents.cremit.io

A reference feed of real-world Non-Human Identity (NHI) credential leak incidents. Maintained by Cremit.

Browse

  • All incidents
  • npm supply chain
  • CI/CD compromise
  • Methodology

Subscribe

  • RSS feed
  • @cremit_io
  • GitHub
// status
monitor active
// build
2026-05-20
// origin
cremit · seoul, kr
// license
CC BY 4.0

© 2026 Cremit. content reuse encouraged with attribution.

campaigns

Active publisher campaigns

A campaign is one publisher account doing either of two coordinated patterns within a 30-day window: two or more distinct package names (multi-name impersonation), or three or more catches on a single name (single-name version pump — e.g. a fake "product" hammered with rapid versions). Sorted by combined weekly downloads (blast radius), not recency: the campaigns that actually hit downstream users surface first.

active campaigns
33
30-day window
combined blast
2.0M/wk
weekly downloads sum
catch events
317
across all campaigns
  • // campaigns/npm/last seen 2026-05-19

    wang1212

    30 · 30 events
    @antv/g-canvas@antv/g-canvaskit@antv/g-lite@antv/g-lottie-player@antv/g-math@antv/g-mobile-canvas@antv/g-mobile-svg@antv/g-mobile-webgl@antv/g-plugin-3d@antv/g-plugin-a11y+20
    combined blast
    387K/wk
    top weekly dl
    267K/wk
  • // campaigns/npm/last seen 2026-05-19

    moayuisuda

    2 · 2 events
    @antv/component@antv/g2
    combined blast
    354K/wk
  • // campaigns/npm/last seen 2026-05-19

    kopiluwaky

    4 · 4 events
    @antv/algorithm@antv/g6-plugin-map-view@antv/gi-assets-xlab@antv/matrix-util
    combined blast
    200K/wk
    top weekly dl
    199K/wk
  • // campaigns/npm/last seen 2026-05-19

    panyuqi

    24 · 24 events
    @antv/a8@antv/attr@antv/d3-color@antv/d3-interpolate@antv/g-layout-blocklike@antv/g-css-typed-om-api@antv/g-base@antv/g-compat@antv/g-css-layout-api@antv/g-mobile+14
    combined blast
    173K/wk
    top weekly dl
    170K/wk
  • // campaigns/npm/last seen 2026-05-19

    banxuan

    5 · 5 events
    @antv/g6-pc@antv/g6-element@antv/g6-plugin@antv/gi-sdk@antv/graphin
    combined blast
    152K/wk
    top weekly dl
    82K/wk
  • // campaigns/npm/last seen 2026-05-19

    kasmine

    2 · 2 events
    @antv/adjust@antv/dom-util
    combined blast
    144K/wk
  • // campaigns/npm/last seen 2026-05-19

    alex_zjt

    21 · 21 events
    @antv/g-gesture@antv/g-image-exporter@antv/g-camera-api@antv/g-components@antv/g-dom-mutation-observer-api@antv/g-mobile-canvas-element@antv/g-pattern@antv/g-plugin-canvas-path-generator@antv/g-plugin-canvas-picker@antv/g-plugin-canvas-renderer+11
    combined blast
    125K/wk
    top weekly dl
    63K/wk
  • // campaigns/npm/last seen 2026-05-19

    atool

    45 · 45 events
    @antv/color-util@antv/data-set@antv/event-emitter@antv/g-perf@antv/g2-extension-plot@antv/g2-ssr@antv/g6-ssr@antv/github-config-cli@antv/gpt-vis-ssr@antv/gpt-vis+35
    combined blast
    124K/wk
    top weekly dl
    120K/wk
  • // campaigns/npm/last seen 2026-05-19refire #34last alerted 30s ago

    lzxue

    20 · 20 events
    @antv/dipper-component@antv/dipper-hooks@antv/g-device-api@antv/l7-map@antv/geo-coord@antv/l7-leaflet@antv/l7-component@antv/l7-core@antv/l7-district@antv/l7-layers+10
    combined blast
    102K/wk
    top weekly dl
    50K/wk
  • // campaigns/npm/last seen 2026-05-19NEWlast alerted 16h ago

    iaaron

    28 · 28 events
    @antv/awards@antv/g6-cli@antv/g6-core@antv/g6-extension-3d@antv/g6-extension-react@antv/g6-react-node@antv/g6@antv/gi-assets-advance@antv/graphlib@antv/hierarchy+18
    combined blast
    81K/wk
    top weekly dl
    71K/wk
  • // campaigns/npm/last seen 2026-05-19NEWlast alerted 1h ago

    newbyvector

    20 · 20 events
    @antv/x6-common@antv/x6-geometry@antv/x6-plugin-clipboard@antv/x6-plugin-dnd@antv/x6-plugin-export@antv/x6-plugin-history@antv/x6-plugin-keyboard@antv/x6-plugin-minimap@antv/x6-plugin-scroller@antv/x6-plugin-selection+10
    combined blast
    68K/wk
    top weekly dl
    32K/wk
  • // campaigns/npm/last seen 2026-05-19

    yiqianyao

    2 · 2 events
    @antv/async-hook@antv/l7-pass
    combined blast
    49K/wk
  • // campaigns/npm/last seen 2026-05-19

    lvisei

    9 · 9 events
    @antv/li-core-assets@antv/li-editor@antv/l7-composite-layers@antv/li-p2@antv/li-sdk@antv/l7plot-component@antv/l7plot@antv/larkmap@antv/li-analysis-assets
    combined blast
    8.5K/wk
    top weekly dl
    8.3K/wk
  • // campaigns/npm/last seen 2026-05-19

    GitHub Actions

    5 · 5 events
    @antv/dumi-theme-antv@antv/mcp-server-antv@antv/s2-vue@antv/s2@cap-js/openapi
    combined blast
    7.7K/wk
  • // campaigns/npm/last seen 2026-05-19NEWlast alerted 16h ago

    zengyue

    15 · 15 events
    @antv/f2-graphic@antv/f-charts@antv/f2-my@antv/f-test-utils@antv/f2-algorithm@antv/f2-context@antv/f2-react@antv/f2-site@antv/f2-vue@antv/f2-wordcloud+5
    combined blast
    6.9K/wk
    top weekly dl
    6.7K/wk
  • // campaigns/npm/last seen 2026-05-19

    neoddish

    7 · 7 events
    @antv/ckb@antv/color-schema@antv/data-samples@antv/data-wizard@antv/lite-insight@antv/thumbnails-component@antv/thumbnails
    combined blast
    239/wk
  • // campaigns/npm/last seen 2026-05-19

    bbsqq

    5 · 5 events
    @antv/ava-react@antv/narrative-text-editor@antv/narrative-text-schema@antv/narrative-text-vis@antv/word-scale-chart
    combined blast
    208/wk
  • // campaigns/npm/last seen 2026-05-19

    openwayne

    11 · 11 events
    @antv/f6-alipay@antv/f6-core@antv/f6-element@antv/f6-hammerjs@antv/f6-plugin@antv/f6-ui@antv/f6-wx@antv/f6@antv/g6-mobile@antv/g6-alipay+1
    combined blast
    149/wk
    top weekly dl
    56/wk
  • // campaigns/npm/last seen 2026-05-19refire #2last alerted 4h ago

    jiulingyun

    6 · 6 events
    @openclaw-cn/cli@openclaw-cn/feishu@openclaw-cn/libsignal@openclaw-cn/toutiao-ops@starmind/collector-cliopenclaw-cn
    combined blast
    135/wk
  • // campaigns/npm/last seen 2026-05-19

    bubkoo

    3 · 3 events
    @antv/x6-components@antv/x6-react@antv/x6-vue3-shape
    combined blast
    116/wk
  • // campaigns/npm/last seen 2026-05-19

    yanxiong

    6 · 6 events
    @antv/dipper-map@antv/l7-draw@antv/l7-editor@antv/l7-extension-g-layer@antv/li-sam-assets@antv/li-aiearth-assets
    combined blast
    76/wk
  • // campaigns/npm/last seen 2026-05-19

    xuying1027

    6 · 6 events
    @antv/f-engine@antv/f-lottie@antv/f-my@antv/f-react@antv/f-vue@antv/f-wx
    combined blast
    76/wk
  • // campaigns/npm/last seen 2026-05-19refire #34last alerted 24s ago

    pddpd

    6 · 6 events
    @antv/chart-linter@antv/dw-analyzer@antv/dw-random@antv/dw-transform@antv/dw-util@antv/knowledge
    combined blast
    63/wk
  • // campaigns/npm/last seen 2026-05-19

    kn9117

    4 · 4 events
    @antv/chart-visualization-skills@antv/gi-cli@antv/scale@antv/util
    combined blast
    55/wk
  • // campaigns/npm/last seen 2026-05-19

    dxq613

    3 · 3 events
    @antv/interaction@antv/istanbul@antv/stat
    combined blast
    53/wk
  • // campaigns/npm/last seen 2026-05-19refire #33last alerted 23s ago

    pomelo-nwu

    3 · 3 events
    @antv/gi-mock-data@antv/gi-public-data@antv/graphin-icons
    combined blast
    50/wk
  • // campaigns/npm/last seen 2026-05-19refire #13last alerted 44s ago

    dewifewi

    2 · 7 events
    did-0091stripe-internal-utils
    combined blast
    —
  • // campaigns/npm/last seen 2026-05-19refire #17last alerted 44s ago

    fwgewgewgewrhgw

    1 · 3 events
    collected-forms-embed-js
    combined blast
    —
  • // campaigns/npm/last seen 2026-05-19

    yzl520

    3 · 3 events
    @lint-md/cli@lint-md/core@lint-md/parser
    combined blast
    —
  • // campaigns/npm/last seen 2026-05-19

    gaofuhong

    4 · 4 events
    @antv/x6-angular-shape@antv/x6-react-shape@antv/x6-vue-shape@antv/x6
    combined blast
    —
  • // campaigns/npm/last seen 2026-05-19

    bqxbqxbqx

    2 · 2 events
    @antv/expr@antv/vendor
    combined blast
    —
  • // campaigns/npm/last seen 2026-05-19

    lviser

    2 · 2 events
    @antv/insight-component@antv/l7-react
    combined blast
    —
  • // campaigns/npm/last seen 2026-05-19

    simaq

    4 · 4 events
    @antv/calendar-heatmap@antv/f2-canvas@antv/g2-brush@antv/gl-matrix
    combined blast
    —

// alerted clusters

5 clusters

Other axes the campaign-detector paged Slack on in the last 7 days — shared exfil destinations, identical payload hashes, typosquat target bursts, and coordinated maintainer-takeover waves. These shapes don't have their own dashboard query, so they only show up here.

  • // owner-change waverefire #34
    active
    227 members·2.0M/wk blast·last alerted 18s ago·first alerted 16h ago
    packages@antv/adjust@antv/ava@antv/dom-util@antv/event-emitter@antv/g-plugin-canvas-path-generator+222
  • // shared NHI targetrefire #33
    AWS credentials file
    5 members·11K/wk blast·last alerted 19s ago·first alerted 15h ago
    packages@antv/x6-plugin-clipboard@antv/layout-wasm@antv/gi-theme-antd@antv/g-plugin-device-renderer@antv/f2
  • // shared NHI targetrefire #34
    SSH private keys
    6 members·295/wk blast·last alerted 19s ago·first alerted 16h ago
    packagesjest-url-loader@antv/my-f2@antv/layout-wasm@antv/f-wx@antv/color-util+1
  • // shared NHI targetrefire #32
    gh CLI token store
    6 members·last alerted 19s ago·first alerted 15h ago
    packagesdid-0091collected-forms-embed-js@openclaw-cn/cli@antv/layout-wasmreact-dom-helper+1
  • // shared NHI targetrefire #10
    AWS IMDS metadata service
    4 members·last alerted 19s ago·first alerted 4h ago
    packagesstripe-internal-utilsdid-0091collected-forms-embed-js+1