started · updated
npm registry targeted by massive malware campaign
A massive software supply chain attack has been identified involving nearly 800 malicious packages on the npm registry. The campaign targets developers across Windows, macOS, and Linux by using AI-generated or typo-squatted package names to evade detection. Once loaded via the Node.js require() function, the packages deploy a Remote Access Trojan (RAT) and an infostealer designed to exfiltrate credentials and sensitive system data.
Research from Sonatype indicates that North Korean-linked threat actors are involved, utilizing Ethereum transactions as a stealthy command-and-control mechanism. Instead of using hard-coded servers, the malware queries an attacker-controlled Ethereum wallet to extract IP addresses for its infrastructure. This technique uses the blockchain as a public dead drop to make the attack more resilient to traditional blocking methods.
The infection chain includes a downloader known as WEL1DROPPER, which can use DNS TXT records to retrieve payload chunks. The campaign has compromised both newly created malicious packages and legitimate existing packages, such as @kolbo/mcp, agentgui, and godot-kit.
Entities
Ethereum · North Korea · Sonatype · npm