Story thread · 2 reports / 2 sources

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

thehackernews.com · 4d

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

How the coverage leans

Across 2 sources · syndicated copies counted once

A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload," OpenSourceMalware researcher Paul

First report: ‘Flooding Dropper’ Is Hitting npm With a Tidal Wave of Malicious Packages devops.com, 4d

The conversation · 0

Sign in to join the conversation.

No comments yet — start the thread.