logo

MUT-8694: An NPM and PyPI Malicious Campaign Targeting Windows Users

ID: eebe447c-ed7a-557f-83aa-a958c0f4469f

STIX ID: report--eebe447c-ed7a-557f-83aa-a958c0f4469f

Feed Name: Datadog Security Labs

Threat Score
85/100

Date Published: 2024-11-22

Date Updated: 2026-04-27

...
...

Datadog Security Research describes an active, cross-ecosystem supply-chain campaign (MUT-8694) that publishes malicious typosquatted packages to PyPI and npm to deliver infostealers (Blank Grabber and Skuld Stealer) to Windows developers; the report includes technical analysis of loaders (obfuscated JS and setup.py PowerShell execution), behavioral TTPs (Defender disabling, persistence, enumeration, credential and crypto theft), IOCs (package names, file hashes, malicious URLs, webhooks/Telegram tokens), and YARA rules to aid detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.