Bottom line: A campaign involving nearly 800 malicious npm packages delivers a cross-platform RAT and infostealer payload for Windows, macOS and Linux.
Security researchers have identified a campaign involving nearly 800 malicious npm packages that deliver malware for Windows, macOS and Linux. Affected are development environments where the packages are unknowingly included as dependencies.
Researcher Paul from OpenSourceMalware discovered a cluster of nearly 800 malicious packages in the npm registry. In his assessment, the packages carry names that either appear AI-generated (“AI slop squatted”) or were created through randomly generated typosquatting — that is, deliberately modeled after typos of common package names to trick developers into installing them by mistake. Despite the different naming, all examined packages deliver the same payload: a combination of a Remote Access Trojan (RAT) and an infostealer that works across Windows, Mac and Linux systems.
For security leaders, the scale of the campaign is significant: nearly 800 packages point to an automated, scalable approach that makes classic manual curation of supply-chain risks more difficult. Since the malware combines both remote access functionality and data-theft capabilities, a single careless installation by a developer could potentially be enough to exfiltrate credentials, session tokens, or other sensitive information from development environments and grant the attacker persistent access to affected systems.
Organizations that use npm as part of their software supply chain should establish automated scanning of dependencies prior to installation, pay particular attention to unusual or recently published packages, and enforce internal policies for the use of third-party packages. Analysis of the specific package names and technical details of the malware payload currently rests primarily with OpenSourceMalware and other security researchers; a complete list of the names of the affected packages was not provided in the original report.
Source: thehackernews.com · Published August 7, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.