Four Malicious npm Packages Steal SSH Keys, Cloud Credentials, and Crypto Wallets
ID: 413aa70f-13a0-5a9b-9524-cbfcfaa9ed91
STIX ID: report--413aa70f-13a0-5a9b-9524-cbfcfaa9ed91
Feed Name: cybersecurityNews.com
Four malicious npm packages distributed via typosquatting (chalk-tempalte, @deadcode09284814/axios-util, axois-utils, and color-style-utils) were discovered to contain infostealers and a Go-based DDoS bot; one package is a near-identical weaponization of the recently leaked Shai-Hulud source. All versions are considered malicious, with active C2 domains/IPs listed, approximately 2,678 weekly downloads combined, and immediate remediation actions recommended (uninstall, rotate credentials, block IOCs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
