logo

Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages

ID: f467f693-02c4-5a2d-8dde-f6812ef8c56e

STIX ID: report--f467f693-02c4-5a2d-8dde-f6812ef8c56e

Feed Name: OpenSourceMalware Blog

Threat Score
85/100

Date Published: 2026-08-06

Date Updated: 2026-08-06

Author: c0a15726-c5b1-4b0d-85e6-fe15553df9e2

...
...

OpenSourceMalware (OSM) reports a rapid campaign that pushed 700+ malicious npm packages which execute when imported and download cross-platform native payloads (Windows, macOS, Linux). The JavaScript first stage fetches executables from rotating Cloudflare Workers hosts and falls back to reconstructing Base64 payloads from DNS TXT records under wel1.ru; native stages include persistence, anti-analysis checks (macOS), and additional beacon stages. The report includes IOCs (package names, Cloudflare hosts, DNS domains, file/process indicators, and SHA-256 hashes) and defender guidance to hunt for imports, TXT lookups, dropped files, and persistence artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.