Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
package-repository-poisoningcredential-stealer-activitybuild-pipeline-compromisethird-party-vendor-breach

Open-source malware and infostealer-driven compromise of developer environments

Updated 3mo agoFirst seen Jan 29, 20262 sources

Threat activity in 2025 increasingly targeted developer environments and software supply chains, with Sonatype reporting more than 450,000 newly identified malicious open-source components and a heavy concentration in the npm ecosystem. Campaigns were characterized by automation and scale: attackers published large batches of similarly named packages, rapidly re-uploaded them after takedowns, and in some cases achieved lateral propagation through developer machines and linked projects, compromising downstream components within days. The reporting highlights a shift away from end-user targeting toward build tools, developer workstations, and CI/CD pipelines, and warns that smaller ecosystems should adopt mature controls (e.g., stronger access controls and 2FA) before abuse scales.

A separate incident illustrates the impact of developer-environment compromise: roughly 860GB of Target source code and internal developer documentation reportedly appeared online, with employees confirming authenticity. Threat researchers assessed the intrusion likely began with an infostealer infection on an employee workstation in late 2025, enabling theft of credentials/session tokens and subsequent access to internal services (e.g., IAM, Confluence, Jira) and code repositories over several months before detection. After discovery, Target reportedly took its Git server offline and tightened VPN/access controls, with internal notes suggesting repository access controls may have been misconfigured—reinforcing the broader trend of attackers using compromised developer endpoints and weakly protected engineering infrastructure to exfiltrate sensitive code and pipeline details.

Share:
Open-source malware and infostealer-driven compromise of developer environments
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Jan 29, 20265mo ago

Sonatype attributes hundreds of malicious npm releases to Lazarus

In the same report, Sonatype attributed hundreds of 2025 malicious npm package releases to North Korea's Lazarus Group. The packages were described as multi-stage malware using droppers, credential theft, persistence, and rapid republishing with reused code and infrastructure.

Sonatype reports surge in malicious open source packages in 2025

Sonatype reported that more than 450,000 new malicious open source components were identified during 2025, with activity heavily concentrated in npm and focused on developer environments, build tools, and CI/CD pipelines. The company said install-time execution was a common tactic for credential theft, payload delivery, and persistence.

Jan 28, 20265mo ago

Target takes Git server offline and restricts VPN access

After discovering the incident, Target reportedly took its Git server offline and limited access to the corporate VPN. Internal memos also referenced an accelerated change to access controls in response to the breach.

Jan 13, 20266mo ago

Employees confirm authenticity of leaked Target data

Current and former Target employees reportedly confirmed by January 13, 2026 that the leaked source code and internal documentation were authentic. Their confirmation validated that the exposed materials belonged to Target's internal environment.

Jan 12, 20266mo ago

Target source code and internal documents appear online

About 860GB of Target source code and internal developer documentation was reported to have appeared online on January 12, 2026. The leak reportedly exposed around 57,000 file and directory names and extensive internal development information.

Oct 1, 20259mo ago

Attacker allegedly conducts months-long exfiltration from Target systems

Using the compromised identity's access to systems including IAM, Confluence, Jira, internal wikis, and Git resources, the attacker reportedly carried out sustained data theft over roughly three to four months. The activity allegedly exposed internal technology stack details, CI/CD information, Hadoop datasets, and engineer metadata.

Sep 30, 20259mo ago

Infostealer reportedly compromises a Target employee workstation

Threat intelligence researchers assessed that the Target source-code theft likely began in late September 2025 with an infostealer infection on an employee workstation. The malware allegedly enabled theft of credentials and session tokens tied to broad internal access.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
Threat actors
1 linked
Organizations
5 linked
SonatypeReversingLabsHelp Net SecurityBleepingComputerTarget
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.