Back to all news
Security

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

The Hacker News·August 7, 2026·1 min read
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

A cluster of nearly 800 malicious packages was published to the npm registry in a campaign delivering cross-platform malware targeting Windows, Mac, and Linux systems. OpenSourceMalware researcher Paul stated the packages use AI slop squatted or randomly generated typo-squatting names. All packages deliver a powerful RAT and infostealer payload, posing a significant supply chain security threat.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store