Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
800 Malicious npm Packages Spread Cross-Platform Malware

800 Malicious npm Packages Spread Cross-Platform Malware

Posted on August 7, 2026 By CWS

A recent surge of nearly 800 harmful packages has hit the npm registry, marking a new wave of malware targeting systems across Windows, Mac, and Linux platforms. This campaign, as highlighted by OpenSourceMalware researcher Paul McCarty, leverages typo-squatting on package names to deliver a potent Remote Access Trojan (RAT) and an infostealer.

Novel Approach in Malware Distribution

Unlike traditional npm software supply chain attacks that rely on lifecycle hooks like preinstall or postinstall scripts to execute malicious code, this newly uncovered threat uses a different tactic. The packages include a README file instructing developers to load them using the require() function, a method for importing modules in various environments.

Once executed, these packages initiate a downloader named WEL1DROPPER, which detects the host’s operating system and processor type. It then retrieves a suitable payload from a selection of Cloudflare Workers domains. If these HTTPS downloads fail, the malware opts for platform-specific domains, utilizing DNS TXT records to secure the next-stage payload from ‘wel1[.]ru’.

Technical Execution and Payload Delivery

Upon executing, the package requests a TXT record, parsing the response to determine the number of payload chunks. It gathers these chunks, decodes them, and transforms them into a binary buffer. The payload is then executed in a temporary directory, using either ‘/bin/sh’ on Linux and macOS or ‘cmd.exe’ on Windows.

The Windows variant takes additional steps to evade detection, such as modifying Event Tracing for Windows (ETW) and the Antimalware Scan Interface (AMSI). It ensures persistence through Registry Run keys and scheduled tasks, while also downloading an encrypted secondary payload. On macOS, the infection chain performs similar actions, seeking out debuggers and analysis tools before retrieving its payload.

Broader Implications and Related Threats

Sonatype, tracking this campaign as Flooding Dropper, notes that the macOS payload suggests potential targeting of Russian financial institutions. This campaign seems to evolve from the dependency confusion strategy named Moika. The development comes amidst reports from Palo Alto Networks Unit 42, which documents attacks on npm and PyPI repositories, delivering various threats like cryptocurrency stealers and cloud credential exfiltration.

Beyond npm packages, threat actors are exploiting Google Chrome extensions disguised as legitimate tools to turn browsers into web crawling proxies. These extensions use an SDK that connects browsers to third-party residential proxy networks, effectively transforming user machines into web scraping tools.

Conclusion and Future Outlook

The identification of such a vast number of malicious npm packages underscores the importance of vigilance in the software supply chain. As cyber threats continue to evolve, developers and organizations must prioritize security measures to safeguard against these sophisticated attacks. Monitoring and updating security protocols will be crucial in mitigating such risks in the future.

The Hacker News Tags:cross-platform malware, Cybersecurity, InfoStealer, Linux, Mac, malicious packages, npm registry, RAT, software supply chain, Windows

Post navigation

Previous Post: Critical Linux SCTP Vulnerability Risks Full Root Access
Next Post: Malware Exploits Windows Hello Keys to Access Entra ID

Related Posts

Turla’s STOCKSTAY Backdoor Targets Ukraine Turla’s STOCKSTAY Backdoor Targets Ukraine The Hacker News
New Investment Scams Use Facebook Ads, RDGA Domains, and IP Checks to Filter Victims New Investment Scams Use Facebook Ads, RDGA Domains, and IP Checks to Filter Victims The Hacker News
New Phishing Attack Targets TikTok Business Accounts New Phishing Attack Targets TikTok Business Accounts The Hacker News
China-Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot Malware China-Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot Malware The Hacker News
Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware The Hacker News
U.S. Halts Foreign Access to Anthropic’s AI Models U.S. Halts Foreign Access to Anthropic’s AI Models The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Malware Exploits Windows Hello Keys to Access Entra ID
  • 800 Malicious npm Packages Spread Cross-Platform Malware
  • Critical Linux SCTP Vulnerability Risks Full Root Access
  • Critical WordPress Vulnerability Allows Remote Code Execution
  • Chrome Exploit Steals Gmail Codes to Hijack Accounts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Malware Exploits Windows Hello Keys to Access Entra ID
  • 800 Malicious npm Packages Spread Cross-Platform Malware
  • Critical Linux SCTP Vulnerability Risks Full Root Access
  • Critical WordPress Vulnerability Allows Remote Code Execution
  • Chrome Exploit Steals Gmail Codes to Hijack Accounts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark