Skip to content

Nearly 800 malicious npm packages spread cross-platform RAT and infostealer

Bottom line: A campaign involving nearly 800 malicious npm packages delivers a cross-platform RAT and infostealer payload for Windows, macOS and Linux.

Security researchers have identified a campaign involving nearly 800 malicious npm packages that distribute malware for Windows, macOS and Linux. Development environments are affected, where the packages are unknowingly pulled in as dependencies.

Researcher Paul from OpenSourceMalware discovered a cluster of nearly 800 malicious packages in the npm registry. In his assessment, the packages carry names that either appear AI-generated (“AI slop squatted”) or were created through randomly generated typosquatting – that is, deliberately mimicking typos of common package names to trick developers into accidental installation. Despite the varying naming, all examined packages deliver the same payload: a combination of a Remote Access Trojan (RAT) and an infostealer that works across platforms on Windows, Mac and Linux systems.

For security leaders, the scale of the campaign is significant: nearly 800 packages point to an automated, scalable approach that makes classic manual curation of supply-chain risks more difficult. Because the malware combines both remote-access functionality and data-theft capabilities, a single careless installation by a developer can potentially be enough to exfiltrate credentials, session tokens or other sensitive information from development environments and grant the attacker persistent access to affected systems.

Organizations using npm as part of their software supply chain should establish automated scanning of dependencies prior to installation, pay particular attention to unusual or recently published packages, and enforce internal policies governing the use of third-party packages. Analysis of the specific package names and technical details of the malware payload currently rests primarily with OpenSourceMalware and other security researchers; a complete list of the affected package names was not provided in the original report.


Source: thehackernews.com · Published August 7, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: