Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

Summary

A campaign has released nearly 800 malicious npm packages onto the registry, designed to deliver a cross-platform Remote Access Trojan (RAT) and infostealer. The packages were found to target Windows, macOS, and Linux operating systems.

IFF Assessment

FOE

The discovery of numerous malicious packages capable of delivering RATs and infostealers poses a significant threat to software developers and organizations relying on the npm ecosystem.

Defender Context

Developers using the npm ecosystem should exercise extreme caution when installing new packages, particularly those with unusual names or from less reputable sources. Thoroughly vetting dependencies and implementing robust software supply chain security practices are crucial to mitigate the risk of such attacks.

Read Full Story →