Hijacked npm and Go packages deploying Python infostealer via VS Code auto-run tasks
Malware Activity
Summary
Hide ▲
Show ▼
Hijacked npm and Go packages now deliver a Python infostealer through a hidden VS Code auto-run task, putting developer machines and credentials at risk across Windows, Linux, and macOS. The payload chain also establishes a socket.io backdoor and uses blockchain-based dead drops to fetch later stages. The activity broadens supply-chain exposure beyond a single package ecosystem and increases the chance of credential, wallet, and developer-data theft.
Related Happenings
Compromised @asyncapi npm packages distributing the Miasma loader
Malware Activity
H score29
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Compromised @asyncapi npm packages distributing the Miasma loader
Malware ActivityAbout this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware Activity
H score9
First: 11.07.2026 20:59
Last: 11.07.2026 20:59
Sources 1
About this happening:
The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware ActivityAbout this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
Malicious npm and PyPI payment SDK typosquat packages
Malware Activity
H score40
First: 09.07.2026 18:09
Last: 09.07.2026 18:09
Sources 1
About this happening:
The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...
Malicious npm and PyPI payment SDK typosquat packages
Malware ActivityAbout this happening: The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...
Rollup polyfill npm package malware activity for remote access and data theft
Malware Activity
H score16
First: 03.07.2026 19:07
Last: 03.07.2026 19:07
Sources 1
About this happening:
Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Rollup polyfill npm package malware activity for remote access and data theft
Malware ActivityAbout this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Miasma supply-chain malware activity
Malware Activity
H score34
First: 10.06.2026 23:27
Last: 10.06.2026 23:27
Sources 1
About this happening:
The Miasma malware activity is enabling supply-chain compromise by stealing build environment and cloud credentials, then using them to poison legitimate packages...
Miasma supply-chain malware activity
Malware ActivityAbout this happening: The Miasma malware activity is enabling supply-chain compromise by stealing build environment and cloud credentials, then using them to poison legitimate packages...
Timeline
-
29.06.2026 08:36 1 articles · 16d ago
Malicious npm packages html-to-gutenberg and fetch-page-assets are uploaded
Untyped PhaseThe malicious npm packages html-to-gutenberg and fetch-page-assets were uploaded to npm, with fetch-page-assets listing html-to-gutenberg as a dependency and setting up the package chain used to deliver the later payloads.
Show sources
- Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer — thehackernews.com — 29.06.2026 08:36
-
29.06.2026 08:36 2 articles · 16d ago
Researchers uncover hijacked npm and Go packages that deploy a Python infostealer
Initial DisclosureJFrog and Nextron Systems documented hijacked npm packages and a cluster of Go packages that hide execution in a VS Code task named "eslint-check", retrieve payloads from blockchain transaction data and TronGrid/Aptos, establish a Socket.io backdoor, and deploy a Python infostealer on Windows, Linux, and macOS.
Show sources
- Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer — thehackernews.com — 29.06.2026 08:36
- Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer — thehackernews.com — 29.06.2026 08:36