Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Stripe, PayPal Ventures bet on India’s Xflow to fix cross-border B2B payments

    February 24, 2026

    Particle’s AI news app listens to podcasts for interesting clips so you you don’t have to

    February 23, 2026

    China’s brain-computer interface industry is racing ahead

    February 22, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Stripe, PayPal Ventures bet on India’s Xflow to fix cross-border B2B payments
    • Particle’s AI news app listens to podcasts for interesting clips so you you don’t have to
    • China’s brain-computer interface industry is racing ahead
    • 6 days left to lock in the lowest Disrupt 2026 rates
    • Google VP warns that two types of AI startups may not survive
    • 7 days until ticket prices rise for Disrupt 2026
    • India’s Sarvam launches Indus AI chat app as competition heats up
    • The creator economy’s ad revenue problem and India’s AI ambitions
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Security»10 npm Packages Caught Stealing Developer Credentials on Windows, macOS, and Linux
    Security

    10 npm Packages Caught Stealing Developer Credentials on Windows, macOS, and Linux

    TechurzBy TechurzOctober 30, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    10 npm Packages Caught Stealing Developer Credentials on Windows, macOS, and Linux
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Oct 29, 2025Ravie LakshmananMalware / Threat Intelligence

    Cybersecurity researchers have discovered a set of 10 malicious npm packages that are designed to deliver an information stealer targeting Windows, Linux, and macOS systems.

    “The malware uses four layers of obfuscation to hide its payload, displays a fake CAPTCHA to appear legitimate, fingerprints victims by IP address, and downloads a 24MB PyInstaller-packaged information stealer that harvests credentials from system keyrings, browsers, and authentication services across Windows, Linux, and macOS,” Socket security researcher Kush Pandya said.

    The npm packages were uploaded to the registry on July 4, 2025, and accumulated over 9,900 downloads collectively –

    • deezcord.js
    • dezcord.js
    • dizcordjs
    • etherdjs
    • ethesjs
    • ethetsjs
    • nodemonjs
    • react-router-dom.js
    • typescriptjs
    • zustand.js

    The multi-stage credential theft operation manifested in the form of various typosquatted packages impersonating popular npm libraries such as TypeScript, discord.js, ethers.js, nodemon, react-router-dom, and zustand.

    Once installed, the malware serves a fake CAPTCHA prompt and displays authentic-looking output that mimics legitimate package installations to give the impression that the setup process is proceeding along expected lines. However, in the background, the package captures the victim’s IP address, sends it to an external server (“195.133.79[.]43”), and then proceeds to drop the main malware.

    In each package, the malicious functionality is automatically triggered upon installation by means of a postinstall hook, launching a script named “install.js” that detects the victim’s operating system and launches an obfuscated payload (“app.js”) in a new Command Prompt (Windows), GNOME Terminal or x-terminal-emulator (Linux), or Terminal (macOS) window.

    “By spawning a new terminal window, the malware runs independently of the npm install process,” Pandya noted. “Developers who glance at their terminal during installation see a new window briefly appear, which the malware immediately clears to avoid suspicion.”

    The JavaScript contained within “app.js” is hidden through four layers of obfuscation — such as XOR cipher with a dynamically generated key, URL-encoding of the payload string, and using hexadecimal and octal arithmetic to obscure program flow — that are designed to resist analysis.

    The end goal of the attack is to fetch and execute a comprehensive information stealer (“data_extracter”) from the same server that’s equipped to thoroughly scan the developer’s machine for secrets, authentication tokens, credentials, and session cookies from web browsers, configuration files, and SSH keys.

    The stealer binary also incorporates platform-specific implementations to extract credentials from the system keyring using the keyring npm library. The harvested information is compressed into a ZIP archive and exfiltrated to the server.

    “System keyrings store credentials for critical services including email clients (Outlook, Thunderbird), cloud storage sync tools (Dropbox, Google Drive, OneDrive), VPN connections (Cisco AnyConnect, OpenVPN), password managers, SSH passphrases, database connection strings, and other applications that integrate with the OS credential store,” Socket said.

    “By targeting the keyring directly, the malware bypasses application-level security and harvests stored credentials in their decrypted form. These credentials provide immediate access to corporate email, file storage, internal networks, and production databases.”

    Caught credentials Developer Linux macOS npm packages stealing Windows
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleGoogle Labs’ free new experiment creates AI-generated ads for your small business
    Next Article Why the AI wearable market is set to grow by 10x – and it’s not just new gadgets
    Techurz
    • Website

    Related Posts

    Opinion

    Simular’s AI agent wants to run your Mac, Windows PC for you

    December 2, 2025
    Security

    AI is becoming introspective – and that ‘should be monitored carefully,’ warns Anthropic

    November 3, 2025
    Security

    Perplexity’s new AI tool lets you search patents with natural language – and it’s free

    November 3, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,059 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202514 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202511 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20252,059 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202514 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202511 Views
    Our Picks

    Stripe, PayPal Ventures bet on India’s Xflow to fix cross-border B2B payments

    February 24, 2026

    Particle’s AI news app listens to podcasts for interesting clips so you you don’t have to

    February 23, 2026

    China’s brain-computer interface industry is racing ahead

    February 22, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.