Skip to content
supplychainattack.orgSupply chain attack incident catalog
activecritical

Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised

On June 24, 2026, an attacker published malicious versions of 20 npm packages belonging to the Leo Platform ecosystem in a coordinated attack. All packages contained an identical CI/CD attack toolkit designed to steal secrets from GitHub Actions runners, cloud credential stores, package registries, and password managers, then exfiltrate them via the victim's GitHub token.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
20 npm packages in the Leo Platform ecosystem; approximately 13,600 downloads per week across affected packages
Ecosystems
Attack vectors
Affected entities
  • Leo Platform packages20 packages compromised with identical CI/CD attack toolkit

On June 24, 2026, a coordinated supply chain attack targeted the Leo Platform ecosystem on npm. An attacker published malicious versions of 20 packages in a burst spanning less than three seconds, indicating a highly automated or pre-planned operation.

All 20 compromised packages carried an identical CI/CD attack toolkit. The malware is designed to steal sensitive credentials from multiple sources: GitHub Actions runners, cloud credential stores, package registries, and password managers. The stolen credentials are then exfiltrated using the victim's own GitHub token, potentially allowing the attacker to maintain persistence and access to downstream systems.

The affected packages collectively receive approximately 13,600 downloads per week, indicating significant exposure across the npm ecosystem. The coordinated nature of the attack and the shared malicious payload suggest a sophisticated threat actor with knowledge of the Leo Platform's package structure and distribution patterns.

Indicators of compromise

Packages
  • Leo Platform packages (20 packages, specific names not listed in source)

Remediation

  • Immediately audit and revoke any GitHub tokens and cloud credentials that may have been exposed on systems that installed the compromised packages
  • Review GitHub Actions logs and cloud provider audit logs for unauthorized access or credential usage during the compromise window
  • Update all Leo Platform packages to patched versions once available from the maintainers
  • Implement package signature verification and integrity checks in CI/CD pipelines
  • Monitor for suspicious credential usage or lateral movement from affected systems
  • Consider using secrets management solutions that limit credential exposure to CI/CD environments

Sources

  1. Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised · StepSecurity

Cite this entry

"Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed June 24, 2026; last updated June 29, 2026. https://supplychainattack.org/incident/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised-kmcbmk

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. activecritical

    ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2

    ChainDrop is a self-propagating npm worm that publishes malicious versions of dozens of npm packages using stolen maintainer credentials. The worm harvests CI/CD credentials and uses an Ethereum-based dead-drop command-and-control mechanism.

    ChaindropnpmOtherCompromised packageMalicious maintainerAccount takeover
  2. containedcritical

    Malicious code in @antv/g6-extension-3d (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-extension-3d, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  3. containedcritical

    Malicious code in gantt-for-react (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including gantt-for-react, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  4. containedcritical

    Malicious code in @antv/gi-sdk-app (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-sdk-app. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit