Cremit
/incidentsfield log
CatchesCampaignsExfilPatternsLLMIncidentsMethodology
↺rss↗cremit.io

incidents.cremit.io

A reference feed of real-world Non-Human Identity (NHI) credential leak incidents. Maintained by Cremit.

Browse

  • All incidents
  • npm supply chain
  • CI/CD compromise
  • Methodology

Subscribe

  • RSS feed
  • @cremit_io
  • GitHub
// status
monitor active
// build
2026-07-17
// origin
cremit · seoul, kr
// license
CC BY 4.0

© 2026 Cremit. content reuse encouraged with attribution.

home/campaigns/npm/doceno

// publisher campaign · npm

doceno

All caught packages published by the doceno account on npm, plus the author + maintainer info the registry currently exposes. Use this view to pivot: shared emails / names across packages are strong evidence of a single attacker behind multiple throwaway handles.

↗npmjs.com publisher↗pypi.org user
packages
3
distinct names
catch events
7
versions × names
blast
557/wk
combined weekly downloads
active span
2026-05-20 → 2026-05-23
first → last catch

// publisher osint

Account-level signals. Activity span tells you how long this handle has been around (fresh = throwaway-prone). Email domains separate single-use webmail from real org addresses. Cross-ecosystem handles + GitHub links are the strongest attribution pivot — same name on multiple registries usually means same operator.

activity on npm
  • packages on registry: 5
  • first publish: 2026-04-26
  • latest publish: 2026-07-10
  • active span: 76d
same handle on other registries
  • npm /~doceno: exists ↗
  • pypi /user/doceno: exists ↗
  • github.com/doceno: exists ↗
email domains
  • gmail.com×3webmail

// shared author identifiers

Same email or author name on more than one package — direct attribution evidence beyond the shared publisher account.

emails
  • daniel.oceno@gmail.com— @stelnyx/apigate, @stelnyx/secgate, @stelnyx/report-theme
author names
  • stelnyx— @stelnyx/apigate, @stelnyx/secgate

// pattern footprint

Static-analysis flags that fired across the campaign, with how many packages each touched. Use as the "what kind of stealer is this" answer.

  • ×2
  • ×2
  • ×2
  • ×1
  • ×1

// full activity on npm

Every package this account currently has on the registry, newest first. ● caught by our pipeline · ○ not yet flagged.3/5 caught.

  • ●
    @ 0.2.14

    Tiny security gate for CI/CD — orchestrates Semgrep, Gitleaks, osv-scanner, Trivy, and npm audit with a premium HTML report.

    2026-07-10
  • ●
    @ 0.3.3

    Tiny static API surface audit — enumerates HTTP endpoints, classifies auth posture, diffs against OpenAPI specs. Zero network, deterministic, one report.

    2026-07-10
  • ●
    @ 0.1.4

    Unified theme + template helpers for Stelnyx CLI reports (LuxScope, LuxFaber, SecGate).

    2026-05-23
  • ○
    @tinydarkforge/arbiter@ 0.1.1

    Deterministic guardrails for TypeScript AI agent loops. Tool-call validation, dollar-cost circuit breakers, loop detection. No LLM dependency.

// packages in this campaign

3 distinct · newest first
  • ↳ author:maintainers: doceno <daniel.oceno@gmail.com>↗ registry
  • ↳ author:Stelnyxmaintainers: doceno <daniel.oceno@gmail.com>↗ registry
  • ↳ author:Stelnyxmaintainers: doceno <daniel.oceno@gmail.com>↗ registry
2026-04-26
  • ○
    @tinydarkforge/engram@ 4.0.3

    Local-first memory and assertion ledger for AI coding agents. Confidence-weighted, contradiction-aware, token-budgeted context over MCP.

    2026-04-26
  • reads-env-vars
    public-github-push
    child-process-spawn
    invokes-secret-scanner
    py-pip-install-runtime
    @stelnyx/secgate
    @stelnyx/apigate
    @stelnyx/report-theme
    AUTO-PUBLISHED/npm/2026-05-23

    @stelnyx/report-theme3 versions·0.1.2→0.1.4

    by doceno

    Unified theme + template helpers for Stelnyx CLI reports (LuxScope, LuxFaber, SecGate).

    weekly
    557
    /wk
    h-score
    55
    size
    80.2 KB
    versions
    4
    AUTO-PUBLISHED/npm/2026-05-20

    @stelnyx/apigate3 versions·0.1.2→0.3.0

    by doceno

    Tiny static API surface audit — enumerates HTTP endpoints, classifies auth posture, diffs against OpenAPI specs. Zero network, deterministic, one report.

    → sends tohttps://github.com/Stelnyx/ApiGate.git
    reads-env-varspublic-github-pushchild-process-spawn

    → No suspicious destination, no remote-exec shape — 1 known-vendor host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    55
    patterns
    3
    size
    148.2 KB
    versions
    4
    AUTO-PUBLISHED/npm/2026-05-19

    @stelnyx/secgate@0.2.13

    by doceno

    Tiny security gate for CI/CD — orchestrates Semgrep, Gitleaks, osv-scanner, Trivy, and npm audit with a premium HTML report.

    → sends tohttps://github.com/Stelnyx/SecGate.git
    invokes-secret-scannerpublic-github-pushreads-env-varspy-pip-install-runtimechild-process-spawn

    → No suspicious destination, no remote-exec shape — 1 known-vendor host(s).

    weekly
    —
    /wk
    llm verdict
    benign 0.85
    h-score
    65
    patterns
    5
    size
    121.5 KB
    versions
    4