Malicious NPM packages fetch infostealer for Windows, Linux, macOS
ID: 5a970524-c3cd-5d5e-8d3e-4f4f55c29cea
STIX ID: report--5a970524-c3cd-5d5e-8d3e-4f4f55c29cea
Feed Name: Bleeping Computer
Threat Score
Ten typosquatted npm packages published on July 4 deliver an obfuscated JavaScript loader that displays a fake ASCII CAPTCHA, fingerprints the host, and downloads a 24MB PyInstaller infostealer which targets system keyrings, browser profiles, SSH keys, OAuth/JWT/API tokens across Windows, macOS, and Linux; the packages accrued nearly 10,000 downloads and exfiltrate stolen data to 195.133.79.43, with the malicious packages remaining available on npm at the time of reporting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
