# Compromised npm package targets developer credentials and remote access

_Published Thursday, October 8, 2026 at 3:06 PM EDT · Security · Latest · Tier 2 — Notable_

![Compromised npm package targets developer credentials and remote access — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgR_DE5ORKWCpLgZgXBuH-MFmuqfxFNnkGQxremc0ffY4dopMHnx-2HvgZTMh48BvVr8k22lGaM__jTS83DuXnLpF4NC9u4bsQF-8_K34gZU0kJS_-10pUSL7WNxecJG0pCiHyNFiqxXEqWP7NqUK2-uvwzo8-ETqwZkPWdNOjhNn5S1Y0uFQX2HGBE5_5J/s1700-nu-rw-lo-l85-e365/t-day.jpg)

StepSecurity identified a hidden payload in version 5.8.3 of the npm package @subql/common that collects credentials and supports remote shell access. The code runs during installation and when the package is imported, targeting developer workstations, continuous integration environments, GitHub Actions runners and accessible cloud services.

Separately, SafeDep found 42 malicious RubyGems packages published by the account reqthrottle_3474, mostly targeting cryptocurrency developers. Eleven open a reverse shell, while 31 download an archive and run its installation script. Those gems remain inactive in continuous integration environments or sandboxes; on developer machines, they wait 20 to 40 minutes before acting.

## Sources

- [The Hacker News](https://thehackernews.com/2026/10/threatsday-ransomware-affiliate.html)

---
Canonical: https://techandbusiness.org/newswire/cleu45_Bi9fmzQ3SiFhclh
Published: 2026-10-08T19:06:49.365Z
Story chronology: 2026-10-08T17:58:02.000Z
Retrieved: 2026-10-08T21:30:34.058Z
Publisher: Tech & Business (techandbusiness.org)
