ThreatCluster

G_Wagon npm Package Steals Browser Credentials via Obfuscated Payload

First seen 27 Jan 2026, 19:53 UTC GbhackersCybersecuritynews 36

Article Content

Browse articles
ThreatCluster

On January 23, 2026, security researchers identified an npm package named ansi-universal-ui, which masqueraded as a legitimate UI component library. This package contained G_Wagon, a sophisticated multi-stage information stealer designed to exfiltrate sensitive browser credentials from users. The malicious payload was heavily obfuscated to evade detection.