Brazil
BRA
On 21 April 2026, malicious releases of legitimate npm packages associated with Namastex Labs, including pgserve and Automagik Genie, were distributed through trusted package channels. Researchers found install-time malware that harvested developer, cloud, CI/CD, npm and PyPI credentials and was capable of using stolen publishing tokens to inject itself into additional packages. StepSecurity confirmed active exfiltration behavior during controlled analysis. The compromise therefore altered legitimate upstream software artifacts and created a direct software-supply-chain data-integrity impact for downstream installations.
Estimated severity
69 / 100
Source reliability
91 / 100
Approximate Date
21/04/2026
Targeted Company
NAMASTEX LABS
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
Brazil
BRA
No other affected countries reported
Target country
Brazil
Affected countries
No information
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Incident Sources
Please rotate your phone