Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages
ID: f467f693-02c4-5a2d-8dde-f6812ef8c56e
STIX ID: report--f467f693-02c4-5a2d-8dde-f6812ef8c56e
Feed Name: OpenSourceMalware Blog
Date Published: 2026-08-06
Date Updated: 2026-08-06
Author: c0a15726-c5b1-4b0d-85e6-fe15553df9e2
OpenSourceMalware (OSM) reports a rapid campaign that pushed 700+ malicious npm packages which execute when imported and download cross-platform native payloads (Windows, macOS, Linux). The JavaScript first stage fetches executables from rotating Cloudflare Workers hosts and falls back to reconstructing Base64 payloads from DNS TXT records under wel1.ru; native stages include persistence, anti-analysis checks (macOS), and additional beacon stages. The report includes IOCs (package names, Cloudflare hosts, DNS domains, file/process indicators, and SHA-256 hashes) and defender guidance to hunt for imports, TXT lookups, dropped files, and persistence artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
