At least 17 fake payment SDKs on npm and PyPI steal development-related access credentials such as API keys and AWS login data through disguised packages that imitate legitimate application programming interfaces.
CISA took over 48 hours to invalidate leaked AWS keys, ignored nine automatic security alerts, and had no defined incident reporting procedures for its own infrastructure.