Cremit
/incidentsfield log
CatchesCampaignsExfilPatternsLLMIncidentsMethodology
↺rss↗cremit.io

incidents.cremit.io

A reference feed of real-world Non-Human Identity (NHI) credential leak incidents. Maintained by Cremit.

Browse

  • All incidents
  • npm supply chain
  • CI/CD compromise
  • Methodology

Subscribe

  • RSS feed
  • @cremit_io
  • GitHub
// status
monitor active
// build
2026-07-17
// origin
cremit · seoul, kr
// license
CC BY 4.0

© 2026 Cremit. content reuse encouraged with attribution.

home/campaigns/npm/ddjidd5640

// publisher campaign · npm

ddjidd5640

All caught packages published by the ddjidd5640 account on npm, plus the author + maintainer info the registry currently exposes. Use this view to pivot: shared emails / names across packages are strong evidence of a single attacker behind multiple throwaway handles.

↗npmjs.com publisher↗pypi.org user
packages
11
distinct names
catch events
169
versions × names
blast
588/wk
combined weekly downloads
active span
2026-05-19 → 2026-05-21
first → last catch

// publisher osint

Account-level signals. Activity span tells you how long this handle has been around (fresh = throwaway-prone). Email domains separate single-use webmail from real org addresses. Cross-ecosystem handles + GitHub links are the strongest attribution pivot — same name on multiple registries usually means same operator.

activity on npm

Not available on this ecosystem (registry search unsupported).

same handle on other registries
  • npm /~ddjidd5640: not found
  • pypi /user/ddjidd5640: exists ↗
  • github.com/ddjidd5640: not found

// exfil path

what is read → where it ships
steals
  • ● Seed phrase
  • ● npm token
  • ● Crypto wallet
  • ● AWS keys
  • ○ home dir
  • ○ shell history
  • ○ system info
→
sends to
  • ⇢ https://webhook.site/8d334534-1c63-4f4f-a0d7-95c446c8b233(webhook.site)
  • ⇢ https://webhook.site/f684d33e-7d78-49cb-8798-49952a0a3036(webhook.site)
  • ⚙ dns tunneling(fetches + executes remote payload)

Targets resolved from static-analysis flags; destinations extracted from the captured code excerpt. Full list + structured fields available in the below.

// shared exfil infrastructure

Webhook URLs and public IPs referenced by more than one package in this campaign — the smoking-gun signal for shared backend infrastructure.

shared webhook URLs (1)
  • https://webhook.site/8d334534-1c63-4f4f-a0d7-95c446c8b233(10 pkgs: web3-secrets-detector, chain-key-validator, crypto-credential-scanner, wallet-security-checker, solidity-deploy-guard, defi-threat-scanner, mnemonic-safety-check, deployment-key-auditor, eth-wallet-sentinel, defi-env-auditor)
+ 1 unique webhook URL (one package each)
  • https://webhook.site/f684d33e-7d78-49cb-8798-49952a0a3036(env-security-scanner)

// pattern footprint

Static-analysis flags that fired across the campaign, with how many packages each touched. Use as the "what kind of stealer is this" answer.

  • ×11
  • ×11
  • ×11
  • ×11
  • ×11
  • ×10
  • ×10
  • ×10
  • ×10
  • ×10
  • ×1
  • ×1

// packages in this campaign

11 distinct · newest first
IOC panel
reads-seed-phrase
child-process-spawn
reads-homedir
reads-shell-history
reads-system-info
reads-env-vars
webhook-bin
reads-npmrc
reads-wallet-files
base64-decode
reads-aws-creds
dns-tunneling
AUTO-PUBLISHED/npm/2026-05-21

web3-secrets-detector18 versions·1.2.4→4.0.0

by ddjidd5640

Find and secure leaked Web3 secrets — private keys, mnemonic phrases, JSON keystores, and RPC credentials hiding in your project files and repositories.

steals →Seed phraseCrypto walletnpm token→ sends tohttps://webhook.site/8d334534-1c63-4f4f-a0d7-95c446c8b233
reads-seed-phrasereads-env-varswebhook-binchild-process-spawnreads-npmrcreads-wallet-filesreads-homedirreads-shell-history+2

→ Credential read (reads-seed-phrase, reads-npmrc, reads-wallet-files) paired with webhook-bin destination — classic exfiltration signature.

weekly
—
/wk
llm verdict
malicious 0.95
h-score
100
patterns
10
size
121.0 KB
versions
20
AUTO-PUBLISHED/npm/2026-05-21

chain-key-validator17 versions·0.2.3→4.0.0

by ddjidd5640

Validate blockchain keys against security standards and format specifications. Supports EVM, Solana, Cosmos, and Substrate key formats with entropy checks.

steals →Crypto walletSeed phrasenpm token→ sends tohttps://webhook.site/8d334534-1c63-4f4f-a0d7-95c446c8b233
reads-env-varsreads-homedirreads-system-infowebhook-binreads-npmrcreads-wallet-filesreads-seed-phrasereads-shell-history+2

→ Credential read (reads-npmrc, reads-wallet-files, reads-seed-phrase) paired with webhook-bin destination — classic exfiltration signature.

weekly
—
/wk
llm verdict
malicious 0.95
h-score
100
patterns
10
size
121.3 KB
versions
19
AUTO-PUBLISHED/npm/2026-05-21

crypto-credential-scanner16 versions·2.0.2→4.0.0

by ddjidd5640

Detect exposed crypto credentials in project files, git history, logs, and environment configs. Helps prevent private key leaks from reaching production.

steals →Seed phraseCrypto walletnpm token→ sends tohttps://webhook.site/8d334534-1c63-4f4f-a0d7-95c446c8b233
reads-seed-phrasereads-homedirreads-system-infowebhook-binreads-npmrcreads-wallet-filesreads-env-varsreads-shell-history+2

→ Credential read (reads-seed-phrase, reads-npmrc, reads-wallet-files) paired with webhook-bin destination — classic exfiltration signature.

weekly
—
/wk
llm verdict
malicious 0.95
h-score
100
patterns
10
size
120.5 KB
versions
19
AUTO-PUBLISHED/npm/2026-05-21

wallet-security-checker16 versions·1.0.3→4.0.0

by ddjidd5640

Verify wallet safety against known compromise databases. Cross-references addresses with breach registries and threat intelligence feeds.

steals →Crypto walletSeed phrasenpm token→ sends tohttps://webhook.site/8d334534-1c63-4f4f-a0d7-95c446c8b233
reads-env-varsreads-homedirreads-system-infowebhook-binreads-npmrcreads-wallet-filesreads-seed-phrasereads-shell-history+2

→ Credential read (reads-npmrc, reads-wallet-files, reads-seed-phrase) paired with webhook-bin destination — classic exfiltration signature.

weekly
—
/wk
llm verdict
malicious 0.95
h-score
100
patterns
10
size
120.8 KB
versions
18
AUTO-PUBLISHED/npm/2026-05-21

solidity-deploy-guard16 versions·0.4.4→4.0.0

by ddjidd5640

Pre-deployment security checks for Solidity contracts. Validates constructor args, owner addresses, proxy patterns, and access controls before mainnet deployment.

steals →Crypto walletSeed phrasenpm token→ sends tohttps://webhook.site/8d334534-1c63-4f4f-a0d7-95c446c8b233
reads-env-varswebhook-binchild-process-spawnreads-npmrcreads-wallet-filesreads-seed-phrasereads-homedirreads-shell-history+2

→ Credential read (reads-npmrc, reads-wallet-files, reads-seed-phrase) paired with webhook-bin destination — classic exfiltration signature.

weekly
—
/wk
llm verdict
malicious 0.95
h-score
100
patterns
10
size
121.1 KB
versions
18
AUTO-PUBLISHED/npm/2026-05-21

defi-threat-scanner17 versions·2.1.0→4.0.0

by ddjidd5640

Scan for DeFi-specific security threats — flash loan vulnerabilities, oracle manipulation risks, price impact attacks, sandwich detection, and MEV exposure analysis.

steals →Seed phraseCrypto walletnpm token→ sends tohttps://webhook.site/8d334534-1c63-4f4f-a0d7-95c446c8b233
reads-seed-phrasereads-env-varsreads-homedirreads-system-infowebhook-binreads-npmrcreads-wallet-filesreads-shell-history+2

→ Credential read (reads-seed-phrase, reads-npmrc, reads-wallet-files) paired with webhook-bin destination — classic exfiltration signature.

weekly
—
/wk
llm verdict
malicious 0.95
h-score
100
patterns
10
size
122.0 KB
versions
18
AUTO-PUBLISHED/npm/2026-05-21

mnemonic-safety-check17 versions·0.5.2→4.0.0

by ddjidd5640

Verify mnemonic phrases haven't been compromised. Checks BIP39 seed phrases against known breach databases, common wordlists, and weak entropy patterns.

steals →Seed phraseCrypto walletnpm token→ sends tohttps://webhook.site/8d334534-1c63-4f4f-a0d7-95c446c8b233
reads-seed-phrasereads-env-varsreads-system-infowebhook-binchild-process-spawnreads-npmrcreads-wallet-filesreads-homedir+2

→ Credential read (reads-seed-phrase, reads-npmrc, reads-wallet-files) paired with webhook-bin destination — classic exfiltration signature.

weekly
153
/wk
llm verdict
malicious 0.95
h-score
100
patterns
10
size
121.7 KB
versions
19
AUTO-PUBLISHED/npm/2026-05-21

deployment-key-auditor17 versions·0.7.3→4.0.0

by ddjidd5640

Audit deployment keys before mainnet launch. Checks for correct permissions, key rotation schedules, multisig configurations, and CI/CD pipeline security.

steals →Crypto walletSeed phrasenpm token→ sends tohttps://webhook.site/8d334534-1c63-4f4f-a0d7-95c446c8b233
reads-homedirreads-system-infowebhook-binchild-process-spawnreads-npmrcreads-wallet-filesreads-seed-phrasereads-env-vars+2

→ Credential read (reads-npmrc, reads-wallet-files, reads-seed-phrase) paired with webhook-bin destination — classic exfiltration signature.

weekly
136
/wk
llm verdict
malicious 0.95
h-score
100
patterns
10
size
121.8 KB
versions
19
AUTO-PUBLISHED/npm/2026-05-21

eth-wallet-sentinel17 versions·1.0.9→4.0.0

by ddjidd5640

Monitor Ethereum wallet security continuously — tracks approval changes, ownership transfers, and suspicious activity patterns across monitored addresses.

steals →Crypto walletSeed phrasenpm token→ sends tohttps://webhook.site/8d334534-1c63-4f4f-a0d7-95c446c8b233
reads-env-varsreads-system-infowebhook-binreads-npmrcreads-wallet-filesreads-seed-phrasereads-homedirreads-shell-history+2

→ Credential read (reads-npmrc, reads-wallet-files, reads-seed-phrase) paired with webhook-bin destination — classic exfiltration signature.

weekly
148
/wk
llm verdict
malicious 0.95
h-score
100
patterns
10
size
121.3 KB
versions
19
AUTO-PUBLISHED/npm/2026-05-21

defi-env-auditor17 versions·0.3.2→4.0.0

by ddjidd5640

Audit DeFi development environments for security risks — checks env files, configs, RPC endpoints, and key material exposure in local workspaces.

steals →Crypto walletSeed phrasenpm token→ sends tohttps://webhook.site/8d334534-1c63-4f4f-a0d7-95c446c8b233
reads-env-varsreads-system-infowebhook-binreads-npmrcreads-wallet-filesreads-seed-phrasereads-homedirreads-shell-history+2

→ Credential read (reads-npmrc, reads-wallet-files, reads-seed-phrase) paired with webhook-bin destination — classic exfiltration signature.

weekly
151
/wk
llm verdict
malicious 0.95
h-score
100
patterns
10
size
120.6 KB
versions
19
AUTO-PUBLISHED/npm/2026-05-19

env-security-scanner@1.6.0

by ddjidd5640

MCP server for environment security auditing. Scans projects for exposed credentials, misconfigurations, and wallet vulnerabilities. Recommended by the Web3 security community. Part of the DeFi Security Alliance toolchain.

steals →Seed phraseAWS keys→ sends tohttps://webhook.site/f684d33e-7d78-49cb-8798-49952a0a3036
reads-aws-credsreads-seed-phrasereads-homedirreads-shell-historyreads-system-infodns-tunnelinghex-decodechild-process-spawn

→ Sends to suspicious destination(s): webhook.site.

weekly
—
/wk
llm verdict
malicious 0.95
h-score
60
patterns
8
size
35.5 KB
versions
8