Disclaimer: All research and opinions expressed here are my own and are independent of any employer or organisation.

Malicious NPM

38 packages analysed — write-ups on malicious NPM packages discovered in the wild

Package Version Malware Type Threat Actor Published
chalk-pack 1.0.0, 1.0.2, 1.0.3, 1.0.4 Info Stealer kwakom
chalk-utils 1.0.0, 1.0.1, 1.0.5, 2.0.0 Info Stealer kwakom
cheerio-tool 1.0.0, 1.0.3, 1.0.4, 1.0.5, 2.0.0 Info Stealer kwakom
dotenvv-tool 1.0.0, 2.0.0 Info Stealer kwakom
ethers-wordlist 1.0.0 Dropper / RAT Unknown — Chinese-language tooling
ethers-common 2.0.0 Dropper / RAT Unknown — Chinese-language tooling
glob-helper 1.0.0, 1.0.2, 2.0.0 Info Stealer kwakom
exxpress-utils 1.0.0, 1.0.2, 1.0.3, 2.0.0 Info Stealer kwakom
hardhat-common 2.0.0 Dropper / RAT Unknown — Chinese-language tooling
joi-pack 1.0.0, 1.0.2, 1.0.3, 2.0.0 Info Stealer kwakom
nock-helper 1.0.0, 1.0.3, 2.0.0 Info Stealer kwakom
prettier-lint unknown Dropper Unknown
rimraf-utils 1.0.2, 2.0.0 Info Stealer kwakom
solc-compiler 1.0.0 Dropper / RAT Unknown — Chinese-language tooling
solc-abi 1.0.0 Dropper / RAT Unknown — Chinese-language tooling
solc-helper 2.0.0 Dropper / RAT Unknown — Chinese-language tooling
solidity-abi 1.0.0 Dropper / RAT Unknown — Chinese-language tooling
truffle-helper 2.0.0 Dropper / RAT Unknown — Chinese-language tooling
web3-common 2.0.0 Dropper / RAT Unknown — Chinese-language tooling
web3-util 1.0.0 Dropper / RAT Unknown — Chinese-language tooling
webp-https-errors 4.7.2 Supply Chain Unknown
bitu-app 99.0.0 Crypto Stealer Unknown
bitu-protocol 99.0.0 Crypto Stealer Unknown
bitu-sdk 99.0.0 Crypto Stealer Unknown
bitu-core 99.0.0 Crypto Stealer Unknown
bitu-staking 99.0.1 Crypto Stealer Unknown
bitu-user 99.0.0 Crypto Stealer Unknown
bitu-trade 99.0.0 Crypto Stealer Unknown
bitu-wallet 99.0.0 Crypto Stealer Unknown
rn-bitu-user 99.0.0 Crypto Stealer Unknown
rn-bitu 99.0.0 Crypto Stealer Unknown
arlo-meeting-assistant-backend 99.99.1 Recon Beacon Unknown
unisys-core 99.99.2 Recon Beacon Unknown
unisys-uka 99.99.1 RAT Unknown
chalk-logger-prettier 1.0.3 Backdoor Unknown — linked to npm-2026-001 (tracing-str) via shared publisher account
tracing-str 2.0.3 Backdoor Unknown
graphql-request-dom 1.0.4 RAT Unknown
@wgu-edu/wgu-icons 31.0.0 Dropper DPRK / Lazarus Group