Cremit
/incidentsfield log
CatchesCampaignsExfilPatternsLLMIncidentsMethodology
↺rss↗cremit.io

incidents.cremit.io

A reference feed of real-world Non-Human Identity (NHI) credential leak incidents. Maintained by Cremit.

Browse

  • All incidents
  • npm supply chain
  • CI/CD compromise
  • Methodology

Subscribe

  • RSS feed
  • @cremit_io
  • GitHub
// status
monitor active
// build
2026-07-17
// origin
cremit · seoul, kr
// license
CC BY 4.0

© 2026 Cremit. content reuse encouraged with attribution.

home/campaigns/npm/58bits

// publisher campaign · npm

58bits

All caught packages published by the 58bits account on npm, plus the author + maintainer info the registry currently exposes. Use this view to pivot: shared emails / names across packages are strong evidence of a single attacker behind multiple throwaway handles.

↗npmjs.com publisher↗pypi.org user
packages
1
distinct names
catch events
4
versions × names
blast
—
combined weekly downloads
active span
2026-05-20 → 2026-05-20
first → last catch

// publisher osint

Account-level signals. Activity span tells you how long this handle has been around (fresh = throwaway-prone). Email domains separate single-use webmail from real org addresses. Cross-ecosystem handles + GitHub links are the strongest attribution pivot — same name on multiple registries usually means same operator.

activity on npm
  • packages on registry: 22
  • first publish: 2025-08-15
  • latest publish: 2026-07-17
  • active span: 336d
same handle on other registries
  • npm /~58bits: exists ↗
  • pypi /user/58bits: exists ↗
  • github.com/58bits: exists ↗
email domains
  • infonomic.io×2
  • gmail.com×1webmail

// exfil path

what is read → where it ships
steals
  • ● Chromium logins
→
sends to

(no destination string extracted — payload may be dynamic / obfuscated)

Targets resolved from static-analysis flags; destinations extracted from the captured code excerpt. Full list + structured fields available in the IOC panel below.

// pattern footprint

Static-analysis flags that fired across the campaign, with how many packages each touched. Use as the "what kind of stealer is this" answer.

  • ×1
  • ×1
  • ×1

// full activity on npm

Every package this account currently has on the registry, newest first. ● caught by our pipeline · ○ not yet flagged.1/22 caught.

  • ○
    @byline/ui@ 4.2.0

    Byline CMS UI package

    2026-07-17
  • ○
    @byline/storage-s3@ 4.2.0

    Byline CMS S3-compatible storage provider (AWS S3, Cloudflare R2, MinIO, etc.)

    2026-07-17
  • ○
    @byline/storage-local@ 4.2.0

    Byline CMS local filesystem storage provider

    2026-07-17
  • ○
    @byline/search-postgres

// packages in this campaign

1 distinct · newest first
  • ↳ author:maintainers: daveamayombo <david@infonomic.io>, infonomic2 <anthony@infonomic.io>, 58bits <anthony.bouch@gmail.com>↗ registry
@ 4.2.0

Byline CMS built-in Postgres full-text search provider

2026-07-17
  • ○
    @byline/richtext-lexical@ 4.2.0

    Byline CMS Lexical richtext editor adapter

    2026-07-17
  • ○
    @byline/i18n@ 4.2.0

    Byline CMS admin interface i18n — translation registry, ICU formatter, React provider, language switcher

    2026-07-17
  • ●
    @byline/host-tanstack-start@ 4.2.0

    TanStack Start host adapter for Byline CMS — server fns, auth context, integration glue, admin shell, and route factories

    2026-07-17
  • ○
    @byline/generated-types@ 4.2.0

    Byline CMS generated collection types — a declaration-merge target populated by each application's @byline/core codegen output

    2026-07-17
  • ○
    @byline/db-postgres@ 4.2.0

    Byline CMS db postgres package

    2026-07-17
  • ○
    @byline/core@ 4.2.0

    Byline CMS core package

    2026-07-17
  • ○
    @byline/client@ 4.2.0

    Byline CMS client API — DSL-like query and mutation layer

    2026-07-17
  • ○
    @byline/cli@ 4.2.0

    Guided installer for Byline CMS into an existing TanStack Start application

    2026-07-17
  • ○
    @byline/auth@ 4.2.0

    Byline CMS auth primitives — actors, abilities, request context, session provider interface

    2026-07-17
  • ○
    @byline/ai@ 4.2.0

    Byline CMS AI subsystem.

    2026-07-17
  • ○
    @byline/admin@ 4.2.0

    Byline CMS admin subsystem — admin users, roles, permissions, account self-service, and the built-in JWT session provider

    2026-07-17
  • ○
    @infonomic/ai@ 2.4.4

    Infonomic AI components.

    2026-07-15
  • ○
    @infonomic/payload-alternative-lexical-editor@ 1.6.6

    An alternative lexical editor for Payload CMS.

    2026-07-15
  • ○
    @infonomic/uikit@ 6.7.7

    Infonomic UI kit is a collection of reusable UI components and utilities for React and Astro.

    2026-07-03
  • ○
    @modulus-learning/agent@ 0.9.1

    Modulus client agent.

    2026-06-10
  • ○
    @infonomic/crypto@ 2.3.0

    Infonomic crypto is a collection of reusable crypto library functions and helper modules.

    2025-09-08
  • ○
    @infonomic/schemas@ 2.4.0

    Infonomic schemas is a collection of reusable Zod 4 schemas and helper methods.

    2025-09-08
  • ○
    @infonomic/shared@ 1.2.0

    Infonomic shared is a collection of reusable library and helper modules.

    2025-08-15
  • public-github-push
    reads-chromium-creds
    reads-env-vars
    AUTO-PUBLISHED/npm/2026-05-20

    @byline/host-tanstack-start4 versions·2.2.2→2.2.6

    by 58bits

    TanStack Start host adapter for Byline CMS — server fns, auth context, integration glue, admin shell, and route factories

    steals →Chromium logins→ sends tohttps://github.com/Byline-CMS/bylinecms.dev
    public-github-pushreads-chromium-credsreads-env-vars

    → No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 2 other host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    89
    patterns
    3
    size
    893.3 KB
    versions
    51