A sophisticated supply-chain attack has been uncovered involving ten malicious npm packages published by the threat actor andrew_r1, targeting Windows, Linux, and macOS developers worldwide. Disguised as legitimate libraries like TypeScript and Discord, these typosquatted packages used deceptive tactics such as fake CAPTCHAs, realistic installation prompts, and heavily obfuscated payloads to perform cross-platform credential theft. The campaign achieved over 9,900 downloads before removal, exploiting npm’s postinstall feature to execute hidden scripts and deploy a 24MB information stealer capable of harvesting system, browser, and authentication credentials. This campaign highlights the rising threat of open-source supply-chain compromises, where a single npm install can silently exfiltrate critical developer data.
Between July 4, 2025, and the following months, ten malicious npm packages were discovered to be part of a multi-stage credential theft operation. Each package employed typosquatting to mimic popular libraries and leveraged npm’s postinstall scripts to trigger immediate malicious execution.
The infection chain began with social engineering — once installed, users were shown a fake CAPTCHA screen that transmitted the victim’s IP address to the attacker’s server for fingerprinting and selective targeting. Upon CAPTCHA completion, the malware downloaded a 24MB cross-platform stealer built using PyInstaller, capable of running natively across Windows, Linux, and macOS.
The payload executed through multiple obfuscation layers — including XOR-based encryption, dynamic keying, and switch-based control-flow confusion — to evade detection and hinder analysis. Once active, the stealer harvested sensitive data from:
The collected information was then archived into ZIP files and exfiltrated via C2 channels to the attacker’s infrastructure. The combination of fake user interactions, cross-OS functionality, and highly obfuscated scripts made this one of the most advanced npm-based campaigns of 2025, underscoring the need for vigilance in open-source dependency management.
package.json for any postinstall or install scripts that open terminals, download binaries, or execute encoded JavaScript — these are red flags.Malicious Packages:deezcord.js, dezcord.js, dizcordjs, etherdjs, ethesjs, ethetsjs, nodemonjs, react-router-dom.js, typescriptjs, zustand.js
IPv4:195.133.79.43
SHA256:80552ce00e5d271da870e96207541a4f82a782e7b7f4690baeca5d411ed71edb
Email:parvlhonor@gmx[.]com
TacticTechniqueDescriptionInitial AccessT1195 / T1195.002Supply Chain Compromise / Compromise Software Supply ChainExecutionT1204 / T1204.002 / T1059 / T1059.007User Execution / Malicious File / Command & Scripting Interpreter (JavaScript)Defense EvasionT1027 / T1027.002 / T1036Obfuscated Files or Information / Software Packing / MasqueradingCredential AccessT1555 / T1555.001 / T1555.003 / T1552 / T1552.001 / T1552.004Credentials from Password Stores, Web Browsers, and FilesDiscoveryT1082 / T1083 / T1614System and Directory Discovery / System Location DiscoveryCollectionT1560 / T1560.001Archive Collected Data / Archive via UtilityExfiltrationT1041Exfiltration Over Command and Control ChannelCommand and ControlT1071 / T1071.001Application Layer Protocol / Web Protocols
Full MITRE Mapping:attack.mitre.org
Report Date: October 31, 2025 | Source: Hive Pro Threat Advisory (TA2025334)
Platform
Arbis AI
The HivePro Platform
Integrations
HiveForce Labs
Compare
vs Rapid7
vs Tenable
vs Qualys
vs Nucleus
Solutions
Attack Surface Mgmt
Multi-Env Scanners
Exposure Assessment
Security Intelligence
Threat Prioritization
Exposure Validation
By Role
CISO
Vulnerability Managers