Digest
CRITICAL

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

A new campaign has flooded the npm registry with almost 800 malicious packages, designed to deliver a powerful cross-platform Remote Access Trojan (RAT) and infostealer. These packages use ‘AI slop squatted’ or typo-squatted names to trick developers. The malware targets Windows, Mac, and Linux systems, posing a significant supply chain risk for developers.

← Back to the feed

Trending Tags