The npm ecosystem is facing a new, sophisticated threat as ten malicious packages have emerged, each designed to automatically run upon installation and deploy a full-blown credential-collecting operation.
See also: 175 malicious npm packages used to collect credentials

This attack campaign represents a significant evolution in supply chain breaches, combining multiple layers of obfuscation with cross-platform interoperability to target developers in Windows, Linux, and macOS environments.
The malware uses typosquatting to mimic popular JavaScript libraries, making detection particularly difficult for unsuspecting developers.
Published on July 4, 2025, these packages remained active for over four months, amassing more than 9,900 downloads in total before analysts recognized their malicious nature.
The perpetrator, operating under the alias andrew_r1, created each package to closely resemble legitimate libraries, including discord.js, ethers.js, TypeScript , and other commonly used development dependencies. This typosquatting approach exploits common spelling errors and variations that developers may inadvertently introduce when installing packages.
Each malicious package leverages postinstall lifecycle hook to execute immediately upon installation, opening in a new terminal window to evade detection during the installation process. The malware's design ensures that it executes independently of the npm install, minimizing the likelihood that developers will notice unusual activity.
The packages include advanced platform detection capabilities, automatically identifying the victim's operating system and deploying the appropriate execution method for Windows command prompts, Linux terminals , or macOS Terminal.app.
See also: CISA: Shai-Hulud worm has compromised 500+ npm packages

The campaign demonstrates advanced technical capabilities through the implementation of four distinct layers of obfuscation. These include a self-decrypting eval wrapper that prevents superficial code inspection, XOR decryption with dynamically generated keys based on the source code of the decryption function, URL encoding of payload strings , and control flow obfuscation using switch-case state machines with mixed hexadecimal and octal arithmetic. This multi-layered approach makes static analysis extremely difficult without full JavaScript evaluation.
After successful installation, the malware presents victims with a fake CAPTCHA prompt designed as a social engineering element. This element serves multiple purposes: it makes the package appear legitimate, delays execution to hide its connection to npm install, requires user interaction that can bypass automated security scans, and convinces developers that they are interacting with a trusted security measure.
The malware's infection mechanism operates through a carefully orchestrated multi-stage process that combines deception with advanced data extraction capabilities. After presenting the fake CAPTCHA, the system performs IP fingerprinting by sending the victim's address to a designated URL, allowing the threat actor to record installations, potentially filter by geographic location, and monitor security researchers' activity.
Once the victim interacts with the CAPTCHA prompt, the malware automatically downloads and executes a 24MB PyInstaller-packaged binary called data_extracter. This cross-platform infostealer targets multiple credential storage mechanisms across all major operating systems.
See also: GitHub: Strengthening npm security with 2FA and short-lived tokens

The binary includes platform-specific implementations for the Linux SecretService D-Bus API and GNOME Keyring, the macOS Keychain Services API, and the Windows Credential Manager.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
