NPM account takeovers via expired maintainer domains
You don't need to exploit npm to poison it. Buy the expired email domain behind a maintainer's account, reset the password, and the package is yours. We scanned 2.1 million packages, extracted 6.7 million maintainer emails, and found 675 expired domains leaving 2,843 packages open to takeover. Those packages sit under 257,000+ dependent repos and 93,000 downstream packages. One lapsed domain renewal, a supply chain full of blast radius.
https://laburity.com/research-npm-account-takeovers/
#SupplyChainSecurity #npm #AccountTakeover #AppSec #Laburity
Remote
0
Followers
0
Following
3
Posts
Joined July 14, 2026
Posts
Open post
Zero to owned: Credential stealer to corporate breach
The breach doesn't start with your infrastructure. It starts on a device you don't control. One dataset of 15 million infostealer logs held 687 million cookies, 43.87 million of them still active session tokens that hand over an account without ever tripping MFA. Your second factor doesn't matter if the attacker inherits the session.
https://darkwiser.com/blog/zero-to-owned-mapping-the-lifecycle-of-a-credential-stealer-to-corporate-breach
#Infostealer #SessionHijacking #MFA #CredentialTheft #dark_web
0
0
0
0
Open post
FortiBleed credentials came out of FortiGate config backups, not a device exploit. The old-password field keeps the previous SHA-256 hash inside the config even after the PBKDF2 upgrade. Invisible in the UI, present in any super_admin backup.
https://darkwiser.com/blog/how-86-644-fortigate-credentials-were-stolen-and-sold
0
0
0
0
Remote instance
infosec.exchange
Open on original server