Cremit
/incidentsfield log
탐지캠페인유출지패턴LLM사고 사례방법론
↺rss↗cremit.io

incidents.cremit.io

실제 발생한 비인간 식별자(NHI) 크리덴셜 유출 사고를 정리한 인덱스. 운영: Cremit

둘러보기

  • 전체 사고
  • npm 공급망
  • CI/CD 침해
  • 방법론

구독

  • RSS 피드
  • @cremit_io
  • GitHub
// 상태
모니터 가동중
// 빌드
2026-05-20
// 출처
cremit · 서울, 대한민국
// 라이선스
CC BY 4.0

© 2026 Cremit. 출처 표시 시 자유롭게 재사용 가능.

홈/token-types/api-key-generic

// 토큰 유형

API Key (generic) 유출

API Key (generic)이(가) 노출된 인덱싱 사고. 공개 일자 기준 정렬.

11건 인덱싱됨

  • 2026-05-19·CRITICAL9.4·confirmed

    AntV npm Account Compromise: Mini Shai-Hulud Wave Hits 323 Packages (May 2026)

    On 2026-05-19 the @antv npm publisher session was used to ship 639 malicious versions across 323 packages, the Mini Shai-Hulud campaign now totals 1,055 versions across 502 packages.

    벡터 / npm supply chain플랫폼 / npm, GitHub, AWS, +2분량 / 22분
  • 2026-05-12·CRITICAL9.5·confirmed

    Mini Shai-Hulud npm Worm: TanStack, UiPath, Mistral AI and 169 Packages Compromised (May 2026)

    npm worm hit 373 versions across 169 packages (@tanstack, @squawk, @uipath, mistralai) via trusted-publishing OIDC abuse and a prepare-script git dep that exfiltrates cloud and registry secrets at install.

    벡터 / npm supply chain플랫폼 / npm, GitHub, AWS분량 / 10분
  • 2026-04-22·CRITICAL9.0·confirmed

    Bitwarden CLI Supply Chain Compromise (2026)

    A malicious build of @bitwarden/cli was published to the public npm registry for roughly 90 minutes, exfiltrating cloud tokens, SSH keys, and AI tooling credentials from CI runners and developer machines.

    벡터 / npm supply chain플랫폼 / npm, GitHub, Bitwarden, +3분량 / 6분
  • 2026-04-19·HIGH7.8·confirmed

    Vercel Context.ai Incident: Environment Variables Accessed via Compromised AI Tool (2026)

    A third-party AI tool used by a Vercel employee was compromised, leading to Google Workspace takeover and access to non-sensitive environment variables in a subset of customer projects.

    벡터 / Third-party AI tool compromise플랫폼 / Vercel분량 / 3분
  • 2024-12-03·CRITICAL8.4·confirmed

    @solana/web3.js Private Key Exfiltration (2024)

    Compromised maintainer publish credentials were used to push two malicious versions of the official @solana/web3.js npm package, embedding a routine that exfiltrated private keys from any wallet using the SDK.

    벡터 / npm supply chain플랫폼 / npm분량 / 5분
  • 2023-01-04·CRITICAL8.6·confirmed

    CircleCI Session Token Breach (2023)

    Malware on a CircleCI engineer's laptop stole a 2FA-backed session token, giving the attacker production access to customer environment variables and any secrets stored in CircleCI.

    벡터 / CI/CD compromise플랫폼 / CircleCI, GitHub, AWS분량 / 3분
  • 2022-10-07·HIGH6.8·confirmed

    Toyota T-Connect Source Code GitHub Leak (2022)

    A subcontractor uploaded T-Connect source code to a public GitHub repository for nearly five years, exposing a database access key for ~296,000 customer records.

    벡터 / Public repo leak플랫폼 / GitHub분량 / 4분
  • 2021-11-04·CRITICAL8.7·confirmed

    rc and coa Coordinated npm Account Takeover (2021)

    Two long-unmaintained npm packages — rc and coa, with combined weekly downloads in the tens of millions — were hijacked the same day and shipped credential-harvesting payloads matching ua-parser-js.

    벡터 / npm supply chain플랫폼 / npm분량 / 5분
  • 2021-10-22·CRITICAL8.8·confirmed

    ua-parser-js npm Account Compromise (2021)

    An attacker took over the maintainer account of ua-parser-js — a package with ~7M weekly downloads — and shipped versions containing a credential stealer (Windows) and a cryptominer (Linux).

    벡터 / npm supply chain플랫폼 / npm분량 / 5분
  • 2021-04-15·CRITICAL9.2·confirmed

    Codecov Bash Uploader Compromise (2021)

    Threat actors modified Codecov's Bash Uploader to exfiltrate environment variables containing tokens, credentials, and keys from CI/CD pipelines across roughly 29,000 affected organizations.

    벡터 / CI/CD compromise플랫폼 / Codecov, GitHub, GitLab, +1분량 / 4분
  • 2018-11-26·HIGH7.4·confirmed

    event-stream / flatmap-stream Backdoor (2018)

    A new maintainer of the popular event-stream npm package added a malicious sub-dependency, flatmap-stream, that exfiltrated cryptocurrency wallet seeds from Copay-derived applications.

    벡터 / npm supply chain플랫폼 / npm분량 / 4분