Typosquatting

Tẹ̀lé

Malicious npm packages steal developer credentials on multiple platforms

Lisa Kern

Ten typosquatted npm packages, uploaded on July 4, 2025, have been found downloading an infostealer that targets sensitive data across Windows, Linux, and macOS systems. These packages, mimicking popular libraries, evaded detection through multiple obfuscation layers and amassed nearly 10,000 downloads. Cybersecurity firm Socket reported the threat, noting the packages remain available in the registry.

Oju opo wẹẹbu yii n lo kuki

A n lo kuki fun àlàyé lati le mu didara oju opo wẹẹbu wa dara. Ka eto imulo wa eto imulo fun alaye diẹ sii.
Kọ