logo

Ongoing typosquatting campaign impersonates hundreds of popular npm packages

ID: 2acb0586-96d7-5fe2-a1e1-770e9c8d6cac

STIX ID: report--2acb0586-96d7-5fe2-a1e1-770e9c8d6cac

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2024-11-05

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Researchers from Phylum, Socket and Checkmarx uncovered an ongoing npm typosquatting campaign that published hundreds of malicious packages impersonating popular JavaScript libraries (e.g., Puppeteer, Husky, testing utilities). The malware is multi-platform (Windows, Linux, macOS), performs host reconnaissance, establishes persistence, steals credentials, and uses Ethereum smart contracts as a novel C2 mechanism, making traditional blocking less effective; multiple SHA-256 hashes and package lists have been published.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.