Researcher: malicious packages lurked on npm for months
ID: 63c4a6bd-5242-50c3-a9df-02d490e6f254
STIX ID: report--63c4a6bd-5242-50c3-a9df-02d490e6f254
Feed Name: Security Ledger
Threat Score
Researchers at ReversingLabs discovered two typosquatting npm packages (nodejs-encrypt-agent and nodejs-cookie-proxy-agent) that embedded a malicious PE identified as TurkoRat, an information-stealing malware; the packages mirrored legitimate modules, went undetected for months, and accumulated roughly 500–700 downloads, posing supply-chain and developer-system infection risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
