BleedWatch
00 // INTEL / MALWARE

Public malware intelligence for exposed build paths.

Malware notes focus on package behavior, build-artifact droppers, credential theft patterns, and infrastructure reuse observed during authorized BleedWatch scanning.

critical

NPM script

postinstall-token-siphon

postinstall script collects npmrc and cloud CLI tokens before forwarding to a rotating endpoint.

First seen 2026-05-05Open
high

PyPI wheel

setup-py-dropper

setup.py executes platform-specific loader and attempts shell history collection.

First seen 2026-05-01Open
high

Docker layer

registry-harvester

entrypoint enumerates mounted registry credentials and posts metadata to public relay.

First seen 2026-04-29Open
medium

GitHub Action

workflow-env-leak

composite action echoes selected environment variables into build artifacts.

First seen 2026-04-23Open
medium

NPM package

typo-aws-sdk-helper

typosquat package mimics common AWS helper and fingerprints project configuration.

First seen 2026-04-18Open
low

PyPI package

telemetry-confuser

package includes excessive telemetry endpoints with unclear disclosure.

First seen 2026-04-13Open
high

Container entrypoint

curlpipe-bootstrap

runtime bootstrap pulls mutable shell script over HTTP before launching service.

First seen 2026-04-07Open
info

Package metadata

maintainer-takeover-cluster

publisher account changed across related package family before suspicious version bump.

First seen 2026-04-02Open

ALREADY SHIPPED

Refresh applied. Live data fed from app.bleedwatch.com.

The public index presents representative indicator structure. Customer-specific malware evidence, hashes, route ownership, and remediation status remain in the authenticated dashboard.