Home / Companies / Socket / Blog / Post Details
Content Deep Dive

10 npm Typosquatted Packages Deploy Multi-Stage Credential Harvester

Blog post from Socket

Post Details
Company
Date Published
Author
Kush Pandya
Word Count
2,559
Company Posts That Month
24
Language
English
Hacker News Points
-
Post removed?
No
Summary

Socket's Threat Research Team uncovered a sophisticated malware operation involving 10 malicious npm packages designed for cross-platform credential theft. The malware, obfuscated through multiple layers, employs social engineering tactics such as displaying fake CAPTCHAs to deceive users into believing the packages are legitimate. It exploits npm's postinstall hook to execute automatically upon installation, harvesting credentials from system keyrings, browsers, and authentication services across Windows, Linux, and macOS. The packages mimic popular libraries through typosquatting, and the operation has accumulated over 9,900 downloads. The malware further employs IP fingerprinting to track victims and downloads a PyInstaller-packaged binary, data_extracter, which efficiently extracts and exfiltrates sensitive information. Organizations are advised to audit their dependencies for these packages, reset credentials, and deploy protective tools like Socket's GitHub app and CLI to mitigate such supply chain attacks.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Real-time 2 6,551 1,245 236 +61%
Kubernetes 1 1,423 250 85 +59%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.