HackerFeeds

CyberSecurity News

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

The Hacker News
· August 7, 2026

AI summary

A large collection of nearly 800 malicious packages has been uploaded to the npm registry as part of a malware campaign. The campaign aims to deliver cross-platform malware that can target Windows, Mac, and Linux systems. The malicious packages use randomly generated names that appear to be typo-squatted, but they all deliver the same payload. This payload consists of a remote access trojan and an infostealer, which can be used to compromise and steal information from infected systems. The packages were identified by OpenSourceMalware researcher Paul, who analyzed the campaign. The malware is designed to be powerful and effective across multiple platforms.

Read the full article at The Hacker Newsthehackernews.com/2026/08/nearly-800-malicious-npm-packages.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.