Security researchers have discovered a new malware campaign that distributes the Skuld info-stealer via malicious packages, posing as legitimate tools. The hackers behind this campaign are tracked as “k303903” and have compromised hundreds of machines.

Subsequent analysis revealed that the “k303903” group likely also operates under the aliases “shegotit2” and “pressurized.” In all cases, identical or very similar tactics, techniques, and procedures (TTPs) for infiltrating the npm ecosystem with malware have been identified.
A recent malicious campaign targeting npm developers delivered the Skuld info-stealer malware. This attack closely resembles a previous attack on Roblox developers.
Threat actors used typosquatting and obfuscation techniques to compromise development machines and steal sensitive data.
See also: Hacker jailed for his involvement in Raccoon Stealer malware
The December campaign leveraged common development methods and relied on commodity malware, highlighting the consistent use of deceptive tactics by these threat actors.
The code snippet reveals a malicious download and execution process. Libraries such as “fs-extra”, “path”, “node-fetch”, and “child_process” are used to download a malicious binary from a URL that has been disguised to appear legitimate. The binary is then executed.
Researchers observed that Obfuscator.io was used to obfuscate the code, making detection difficult. Once installed, the malware retrieves and executes the final payload (Skuld info stealer malware) under the filename download.exe.
The hacking group k303903 used typosquatting to upload malicious npm packages (that looked like popular libraries), which tricked developers into installing them . As a result, data could be extracted via a Discord webhook.
The use of seemingly legitimate commands and trusted services (replit.dev) further conceals malicious intent, which highlights the importance of carefully reviewing the package before installation.
See also: Hackers use RedLine Stealer to steal credentials
Malicious npm packages were downloaded more than 600 times, stealing credentials and sensitive data from users. Despite the swift removal of the npm registry, the impact was significant.
To mitigate these risks, developers should implement a layered security approach. Using automated tools can help proactively detect and identify malicious dependencies within the development lifecycle, intercepting threats before they compromise systems.

General tips for protection against info-stealer malware like Skuld
First, it is important to keep updated operating systems and applications, as these updates often include security fixes that can protect devices from these types of attacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Second, it is recommended to use strong, unique passwords. This can help protect accounts from being hacked.
See also: macOS Malware Banshee Stealer Source Code Leaked
Third, educating users about the dangers of malware is essential. Users should know the signs of suspicious emails and avoid clicking on suspicious links.
Finally, the need for using security solutions that provide real-time protection and have the ability to detect and remove malware is emphasized.
Source: gbhackers.com
