
- Ten typosquatted npm packages delivered infostealing malware to nearly 10,000 systems
- Malware targeted system keyrings, bypassing app-level security to steal decrypted credentials
- Affected users must revoke credentials, rebuild systems, and enable multi-factor authentication
Almost a dozen malicious npm packages, delivering dangerous infostealing malware, were downloaded roughly 10,000 times before being spotted and removed.