logo

Malicious NPM package uses Unicode steganography to evade detection

ID: 9078072c-8e5a-506e-a40b-e1549afa64d0

STIX ID: report--9078072c-8e5a-506e-a40b-e1549afa64d0

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-05-15

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A malicious NPM package, os-info-checker-es6, was updated to include obfuscated install scripts and a sophisticated C2 that hides data using invisible Unicode variation selectors and retrieves a base64-encoded stage-2 payload via Google Calendar links; the package (and several dependent packages) has been downloaded over 1,000 times, includes persistence and eval-based execution, and remains listed on the NPM registry despite disclosure to maintainers and prior reporting by other researchers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.