G_Wagon npm Package Steals Browser Credentials via Obfuscated Payload
First seen 27 Jan 2026, 19:53 UTC
•
•36
Export
Article Content
Browse articles
On January 23, 2026, security researchers identified an npm package named ansi-universal-ui, which masqueraded as a legitimate UI component library. This package contained G_Wagon, a sophisticated multi-stage information stealer designed to exfiltrate sensitive browser credentials from users. The malicious payload was heavily obfuscated to evade detection.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Active Exploitation of GitLab CVE-2026-19478 and Microsoft Entra ID Flaw
Sandworm Launches Wiper Malware Campaign Against Ukrainian Organizations
Malware Spread via Fake Polymarket Trading Bot Targets DeFi Developers
ShinyHunters Exploits Oracle PeopleSoft Zero-Day Vulnerability
North Korean Hackers Target Open Source Software Supply Chain via npm Packages
NPM Packages Distribute PylangGhost RAT in Supply Chain Attack