• Sources: analysis, discussion
  • Summary: Socket states that keyv@6.0.0 carried a passing npm provenance attestation, because the legitimate release workflow built already-trojanized source, so provenance attested build integrity and not source integrity. Socket also describes a host-level watcher, persisted as a macOS LaunchAgent or a Linux systemd user service, that polls the GitHub API with the stolen token every 60 seconds. It evaluates a remote-supplied handler string the moment that token returns an HTTP 4xx.
  • Why it matters: Rotating the stolen credentials first is what arms the watcher, so removal of the implant has to precede rotation, and a passing attestation answers build integrity rather than source integrity.

send feedback on this story