Find notable cyber news and cases, enriched with sources, timelines, and signals.

Hijacked npm and Go packages deploying Python infostealer via VS Code auto-run tasks

Malware Activity
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

Hijacked npm and Go packages now deliver a Python infostealer through a hidden VS Code auto-run task, putting developer machines and credentials at risk across Windows, Linux, and macOS. The payload chain also establishes a socket.io backdoor and uses blockchain-based dead drops to fetch later stages. The activity broadens supply-chain exposure beyond a single package ecosystem and increases the chance of credential, wallet, and developer-data theft.

Related Happenings

Compromised @asyncapi npm packages distributing the Miasma loader

Malware Activity
H score29 First: 15.07.2026 12:16 Last: 15.07.2026 12:16 Sources 1

About this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....

Jscrambler 8.14.0 malicious preinstall infostealer release

Malware Activity
H score9 First: 11.07.2026 20:59 Last: 11.07.2026 20:59 Sources 1

About this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...

Malicious npm and PyPI payment SDK typosquat packages

Malware Activity
H score40 First: 09.07.2026 18:09 Last: 09.07.2026 18:09 Sources 1

About this happening: The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...

Rollup polyfill npm package malware activity for remote access and data theft

Malware Activity
H score16 First: 03.07.2026 19:07 Last: 03.07.2026 19:07 Sources 1

About this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...

Miasma supply-chain malware activity

Malware Activity
H score34 First: 10.06.2026 23:27 Last: 10.06.2026 23:27 Sources 1

About this happening: The Miasma malware activity is enabling supply-chain compromise by stealing build environment and cloud credentials, then using them to poison legitimate packages...

Timeline

  1. 29.06.2026 08:36 1 articles · 16d ago

    Malicious npm packages html-to-gutenberg and fetch-page-assets are uploaded

    Untyped Phase

    The malicious npm packages html-to-gutenberg and fetch-page-assets were uploaded to npm, with fetch-page-assets listing html-to-gutenberg as a dependency and setting up the package chain used to deliver the later payloads.

    Show sources
  2. 29.06.2026 08:36 2 articles · 16d ago

    Researchers uncover hijacked npm and Go packages that deploy a Python infostealer

    Initial Disclosure

    JFrog and Nextron Systems documented hijacked npm packages and a cluster of Go packages that hide execution in a VS Code task named "eslint-check", retrieve payloads from blockchain transaction data and TronGrid/Aptos, establish a Socket.io backdoor, and deploy a Python infostealer on Windows, Linux, and macOS.

    Show sources