Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Surveillance Malware Hidden in npm and PyPI Packages Targets Developers with Keyloggers, Webcam Capture, and Credential Theft

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
1,134
Company Posts That Month
23
Language
English
Hacker News Points
-
Post removed?
No
Summary

Surveillance malware has been discovered hidden within four npm and PyPI packages, collectively exceeding 56,000 downloads, targeting developers with covert monitoring tools such as keyloggers, webcam capture, and credential theft mechanisms. The packages—dpsdatahub, nodejs-backpack, m0m0x01d, and vfunctions—employ sophisticated techniques like invisible iframes, obfuscated exfiltration endpoints, and dynamic data transmission to evade detection, exfiltrating sensitive information through channels such as Slack, AWS Lambda, and Gmail SMTP. While dpsdatahub acts as a persistent keylogger, nodejs-backpack performs unauthorized system profiling under the guise of a development utility, and m0m0x01d leverages Burp Collaborator for credential harvesting. Meanwhile, vfunctions remains dormant until explicitly invoked, at which point it enables full surveillance capabilities, including webcam capture and self-replication. The revelation of these packages underscores a growing trend where threat actors exploit trusted ecosystems to integrate spyware into developer workflows, raising concerns about the future persistence and modularity of such surveillance-focused malware in supply chains.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.