news.mlab.sh
Back to the feed
threat-intel

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

High
Image: The Hacker News
Summary

A sophisticated campaign involving nearly 800 malicious npm packages has been deployed to deliver cross-platform malware – a Remote Access Trojan (RAT) and infostealer – targeting Windows, macOS, and Linux systems. The packages utilize a complex downloader and telemetry system to evade detection, and are linked to a previous campaign (Moika) and ongoing efforts to exploit npm and PyPI. The campaign is suspected to be targeting Russian financial institutions and mobile payments, and has expanded to include Google Chrome extensions used as web crawling proxies.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.