Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

Nearly 800 malicious npm packages have been published to deliver a cross-platform remote access trojan and infostealer, using AI-generated or typo-squatted names to target Windows, Mac, and Linux systems.

Nearly 800 malicious packages were published to the npm registry in a campaign delivering cross-platform malware targeting Windows, Mac, and Linux systems. The packages use AI slop-squatted or randomly generated typo-squatting names, but all deploy a powerful remote access trojan (RAT) and infostealer payload, according to OpenSourceMalware researcher Paul.