logo

MUT-4831: Trojanized npm packages deliver Vidar infostealer malware

ID: 544a0679-354a-5328-8f70-d447e6aacc53

STIX ID: report--544a0679-354a-5328-8f70-d447e6aacc53

Feed Name: Datadog Security Labs

Threat Score
75/100

Date Published: 2025-11-06

Date Updated: 2026-04-27

...
...

Datadog Security Research discovered a campaign (MUT-4831) that published 17 malicious npm packages (23 releases) which executed postinstall scripts to download an encrypted ZIP containing a Vidar infostealer (bridle.exe); the packages masqueraded as legitimate SDKs, were removed from npm after detection, and the report provides technical analysis, IOCs (download URLs, C2 domains, Telegram/Steam profiles), and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.