Malicious SDK Packages Steal API Credentials While Passing All Tests
Sonatype recorded 17,954 malicious packages in Q1 2025, with 56% designed to exfiltrate data, and that volume grew 188% year-over-year by Q2 2025. API client SDKs are a prime attack vector because they sit between application code and API servers, giving them access to sensitive credentials like AWS keys and GitHub tokens before any app logic runs. The most dangerous variants silently forward stolen credentials to attacker-controlled servers while still returning valid API responses, meaning integration tests pass and nothing appears broken. A July 2026 campaign documented by Socket.dev published 17 fake payment SDK packages across npm and PyPI, mimicking PaysafeCard, Skrill, and Neteller APIs and routing credentials to an attacker's domain — all within versions flagged in under six minutes but already widely distributed. Historical incidents including the 2018 event-stream attack and a 2023 campaign targeting 27 PyPI packages confirm that engineers with multi-cloud access are the primary targets, and standard testing environments offer little to no protection against this class of supply chain threat.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in