Dangerous NPM packages target developer credentials on Windows, Linux and Mac – here’s what we know


  • Ten typosquatted NPM packages delivered information-stealing malware to nearly 10,000 systems.
  • The malware targeted system keyrings, bypassing application-level security to steal decrypted credentials.
  • Affected users should revoke their credentials, rebuild systems, and enable multi-factor authentication.

Nearly a dozen malicious NPM packages, distributing dangerous information-stealing malware, were downloaded approximately 10,000 times before being spotted and removed.

Recently, Socket security researchers found 10 packages on npm targeting software developers, particularly those who use the Node Package Manager (npm) ecosystem to install JavaScript and Node.js libraries.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top