As cited
Copy frozen at (site build).
threat intel
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
Nearly 800 malicious packages were published to the npm registry, using typo-squatting and randomly generated names to deliver a cross-platform remote access trojan (RAT) and infostealer capable of targeting Windows, Mac, and Linux systems. The campaign exploited the npm package ecosystem to distribute malware with obfuscated names designed to evade detection.
Why it matters: Developers using npm are at direct risk of installing compromised dependencies; audit your project dependencies immediately and check for any packages with suspicious names or recent installation dates from this campaign.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
Nearly 800 malicious packages were published to the npm registry, using typo-squatting and randomly generated names to deliver a cross-platform remote access trojan (RAT) and infostealer capable of targeting Windows, Mac, and Linux systems. The campaign exploited the npm package ecosystem to distribute malware with obfuscated names designed to evade detection.
Why it matters: Developers using npm are at direct risk of installing compromised dependencies; audit your project dependencies immediately and check for any packages with suspicious names or recent installation dates from this campaign.
- Source published
- First seen by Cybersecurity Tracker