Cremit
/incidentsfield log
CatchesCampaignsExfilPatternsLLMIncidentsMethodology
↺rss↗cremit.io

incidents.cremit.io

A reference feed of real-world Non-Human Identity (NHI) credential leak incidents. Maintained by Cremit.

Browse

  • All incidents
  • npm supply chain
  • CI/CD compromise
  • Methodology

Subscribe

  • RSS feed
  • @cremit_io
  • GitHub
// status
monitor active
// build
2026-05-20
// origin
cremit · seoul, kr
// license
CC BY 4.0

© 2026 Cremit. content reuse encouraged with attribution.

campaigns/shared NHI target

Browser saved logins

browser-login-data
members
2
combined blast
—
last alerted
—
fire count
0

// members

Every caught package that currently matches this cluster's axis, replayed live over the last 7 days. Snippets show where the cluster identifier appears in the package's static excerpt or which takeover heuristic fired.

  • npm/@antv/li-aiearth-assets·@0.4.7·18h ago·yanxiong
    var canvas = document.createElement('canvas'); var ctx = canvas.getContext('2d'); var img = new Image(); img.crossOrigin = 'Anonymous'; img.src = imgUrl; return new Promise(function (resolve) { img.onload = function () { canvas.width = img.

    llm: No suspicious destination, no remote-exec shape — 1 known-vendor host(s).

  • npm/·@1.4.2·18h ago·
    let imports = {}; imports['__wbindgen_placeholder__'] = module.exports; let wasm; const { TextDecoder, TextEncoder } = require(`util`);

    llm: No suspicious destination, no remote-exec shape — 1 known-vendor host(s).

@antv/layout-wasm
iaaron
← back to all campaigns