QUIETVAULT is a JavaScript credential stealer focused on harvesting developer secrets, especially GitHub and npm tokens, from compromised systems. It has been observed in active operations, including software supply-chain compromise activity, where malicious package installation triggered execution of the stealer. QUIETVAULT collects environment variables, system information, and access tokens, then exfiltrates the stolen data, including by publishing it to attacker-controlled GitHub repositories.
A distinguishing characteristic of QUIETVAULT is its abuse of AI tooling already present on the victim host. The malware checks for locally installed AI command-line assistants and submits predefined natural-language prompts to direct those tools to search the filesystem for configuration data and other sensitive material. Reported targets include developer credentials, cloud-related secrets, wallet-related files, and other high-value configuration artifacts. This reflects a "living off the AI" approach in which legitimate local AI utilities are repurposed to expand secret discovery and improve post-compromise collection.
QUIETVAULT has been reported on macOS and Linux hosts, with emphasis on developer environments where local AI CLI tools and source-control credentials are likely to be present. Its observed role is credential theft and secret discovery rather than persistence or destructive action. Public reporting has linked its use to supply-chain compromise scenarios and broader attacker efforts to accelerate data theft through AI-assisted on-host reconnaissance and exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The packages were found to embed a postinstall script that, in turn, launched a JavaScript credential stealer named QUIETVAULT to siphon environment variables, system information, and valuable tokens, including GitHub Personal Access Tokens (PATs), by weaponizing a Large Language Model (LLM) tool already installed on the endpoint to perform the search.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Where an entry vector is documented, it was conventional — a server-side request forgery (SSRF), a known CVE, stolen credentials.
Mandiant investigated a supply chain compromise involving the QUIETVAULT credential stealer...
QUIETVAULT is a credential-theft variant. The JavaScript stealer exfiltrates GitHub and NPM tokens to an attacker-controlled GitHub repo...
The marimo case is the clean demonstration: an ATA gained entry through an ordinary CVE, then composed the entire post-exploitation chain live — credential harvesting, an AWS Secrets Manager call, an SSH pivot, a full PostgreSQL exfiltration — in under 10 hours...
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
JavaScript credential stealer that leverages local AI CLI tools to locate and exfiltrate secrets.
JavaScript credential stealer that exfiltrates GitHub and NPM tokens and leverages whatever AI CLI is installed on the victim to search for additional secrets.
Credential stealer observed checking compromised machines for AI command-line tools and using predefined prompts to locate configuration files and steal GitHub and NPM tokens.
Credential stealer observed searching compromised machines for command-line AI tools, then using predefined prompts to locate configuration files and collect GitHub and NPM tokens.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.