Skip to content
Back to the blog
Supply chain June 20, 2026

Fake npm packages imitate well-known tools to slip a trojan into Windows

Security researchers have uncovered a software supply chain attack campaign targeting developers who use Node.js. An attacker published several malicious packages on the npm registry whose names deliberately resembled a legitimate and very popular library with millions of weekly downloads. The strategy was not the typical typo, but choosing names credible enough to go unnoticed in a quick dependency review. Installing just one of them in a project was enough to compromise the developer’s computer.

The malware worked in stages to go unnoticed. When the package was imported, encrypted code was decrypted and launched a script that downloaded the next stage from a domain posing as a drivers website, disguising the download as a Windows patch. The end result was a remote access trojan (RAT) able to control the computer, stay active after a reboot, detect analysis environments and steal passwords saved in the browser. In practice, the criminals gained full control of the infected computer.

Tip from Soporte Informático 360

Before installing any package, check the exact name, the number of downloads and the official publisher. Use a version lock file, run dependency audit tools and be wary of newly created packages with very few downloads.

Source: The Hacker News. Summary prepared by our team for informational purposes.

Do you think a device may be compromised?

We help you check it, clean it and protect it. Write to us with no obligation.

Get help