Glassworm Hits Popular React Native Packages With Credential-Stealing npm Malware
ID: ce6e496d-ee09-5b18-aa7d-87c13304ca94
STIX ID: report--ce6e496d-ee09-5b18-aa7d-87c13304ca94
Feed Name: cybersecurityNews.com
A coordinated supply-chain attack on March 16, 2026 inserted a malicious preinstall hook (install.js) into [email protected] and [email protected], causing npm installs to execute an obfuscated multi-stage Windows payload that used Solana transaction memos and Google Calendar as relays; the final stealer persisted via Task Scheduler/Run registry and exfiltrated cryptocurrency wallets, npm tokens, and GitHub credentials. Developers should audit lockfiles for the specified versions, treat affected machines as compromised, rotate credentials and wallet keys, and review outbound connections to 45.32.150.251 and 217.69.3.152.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
