logo

Researcher: malicious packages lurked on npm for months

ID: 63c4a6bd-5242-50c3-a9df-02d490e6f254

STIX ID: report--63c4a6bd-5242-50c3-a9df-02d490e6f254

Feed Name: Security Ledger

Threat Score
65/100

Date Published: 2023-05-18

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

Researchers at ReversingLabs discovered two typosquatting npm packages (nodejs-encrypt-agent and nodejs-cookie-proxy-agent) that embedded a malicious PE identified as TurkoRat, an information-stealing malware; the packages mirrored legitimate modules, went undetected for months, and accumulated roughly 500–700 downloads, posing supply-chain and developer-system infection risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.