Nearly 800 Malicious npm Packages Hit Windows, macOS and Linux via Typosquatted Names

Nearly 800 Malicious npm Packages Hit Windows, macOS and Linux via Typosquatted Names

A campaign has been uncovered in the npm registry, with around 800 malicious packages distributing cross-platform malware to Windows, Mac, and Linux systems. Researcher Paul McCarty from OpenSourceMalware said the packages use generated or "AI slop" typosquatted names, but all deliver a powerful remote access trojan and information stealer.

Unlike typical npm supply chain attacks that rely on lifecycle hooks like preinstall or postinstall to trigger malicious code execution, these packages include a README instructing developers to load them via require() — a built-in function for importing modules, local files, and third-party packages. The attack triggers a downloader named WEL1DROPPER, which identifies the host operating system and CPU architecture, then fetches a compatible payload from one of three Cloudflare Workers hosts: oob-worker.cf103-070.workers.dev, oob-worker.cf102-baf.workers.dev, or oob-worker.cf99-9b3.workers.dev.

If HTTPS downloads fail, the malware switches to a platform-specific domain and uses DNS TXT records to obtain the next stage from wel1.ru. For Linux x64, it uses sdk.dl.wel1.ru; for Linux ARM64, ext.dl.wel1.ru; for macOS, pkg.dl.wel1.ru; and for Windows, net.dl.wel1.ru. McCarty explained that the package first requests a TXT record from c. , parses the response as the number of payload chunks (accepting a value between 1 and 2,000), then requests numbered TXT records, joins the returned strings, and Base64-decodes them into a binary buffer.

In the final stage, the payload is written to a temporary folder and executed via /bin/sh on Linux and macOS, or cmd.exe on Windows. Sonatype, tracking the campaign as Flooding Dropper, said the final stage runs as a detached process, with the Windows version attempting to patch Event Tracing for Windows (ETW) and Antimalware Scan Interface (AMSI) to hinder monitoring, checking for sandboxes and virtual environments, establishing persistence via a Registry Run key and a scheduled task, and downloading and executing an encrypted payload /pkg/update_win.exe. The macOS infection chain is similar, performing the same checks and actions.

Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate