QUIETVAULT is a JavaScript-based credential stealer associated with malicious npm package supply-chain activity. It harvests developer secrets, including GitHub personal access tokens and npm tokens, along with environment variables and host-system information. It searches compromised endpoints for locally installed AI command-line tools and submits predefined natural-language prompts to locate configuration files and additional secrets, including cloud credentials, private keys, SSH-related material, and cryptocurrency-wallet data. Collected data is exfiltrated through attacker-controlled public GitHub repositories using available local credentials. QUIETVAULT was deployed through trojanized npm packages whose post-installation scripts executed the stealer. A supply-chain intrusion involving the compromised Nx ecosystem and subsequent cloud compromise was attributed to UNC6426; stolen developer credentials were used to access CI/CD secrets and cloud environments. QUIETVAULT has been observed targeting macOS and Linux hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The packages were found to embed a postinstall script that, in turn, launched a JavaScript credential stealer named QUIETVAULT to siphon environment variables, system information, and valuable tokens, including GitHub Personal Access Tokens (PATs), by weaponizing a Large Language Model (LLM) tool already installed on the endpoint to perform the search.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Where an entry vector is documented, it was conventional — a server-side request forgery (SSRF), a known CVE, stolen credentials.
Mandiant investigated a supply chain compromise involving the QUIETVAULT credential stealer...
"...push trojanized versions of the package to the npm registry. The packages were found to embed a postinstall script that, in turn, launched a JavaScript credential stealer..."
QUIETVAULT is a credential-theft variant. The JavaScript stealer exfiltrates GitHub and NPM tokens to an attacker-controlled GitHub repo...
The marimo case is the clean demonstration: an ATA gained entry through an ordinary CVE, then composed the entire post-exploitation chain live — credential harvesting, an AWS Secrets Manager call, an SSH pivot, a full PostgreSQL exfiltration — in under 10 hours...
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
JavaScript credential stealer that leverages local AI CLI tools to locate and exfiltrate secrets.
JavaScript credential stealer that exfiltrates GitHub and NPM tokens and leverages whatever AI CLI is installed on the victim to search for additional secrets.
Credential stealer observed checking compromised machines for AI command-line tools and using predefined prompts to locate configuration files and steal GitHub and NPM tokens.
Credential stealer observed searching compromised machines for command-line AI tools, then using predefined prompts to locate configuration files and collect GitHub and NPM tokens.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.