ShellCodeX Intelligence Brief
CRITICAL
Open Source
Nearly 800 Malicious npm Packages Ship Cross-Platform RAT and Infostealer
Source headline: Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
Threat level
Critical
Signal strength
85/100
Source confidence
1 source
Published
4 hours ago
Intelligence Summary
A large batch of malicious packages has appeared on the npm registry, aiming to compromise Windows, macOS, and Linux systems. The packages use squatted or randomly generated typo-squatting names to blend in with legitimate dependencies. When installed, they deliver a remote access trojan (RAT) and an infostealer payload. This increases risk for developers and CI/CD environments that automatically install npm dependencies. Users should audit npm dependencies, monitor for unexpected package installs, and remove suspicious or untrusted packages immediately.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.
Topics
Original reporting
The Hacker News
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
Open original source