logo

Rogue npm Packages Target Developers SSH Keys, Cloud Tokens, and Crypto Wallet Data

ID: 315700b8-b05c-5ee7-9b54-1ef0451e0622

STIX ID: report--315700b8-b05c-5ee7-9b54-1ef0451e0622

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Varshini

...
...

*Executive summary:* A recent typosquatting campaign on the npm ecosystem advertises four malicious packages that steal developer credentials and cloud keys, target cryptocurrency wallets, and deploy a persistent Go-based DDoS bot; the report includes IOCs (malicious C2 domains and an IP:port), attributes reuse of Shai-Hulud code, and urges removal of the packages and cleanup of related configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.