Cybersecuritynews
Malicious 'duer-js' NPM Package Distributes 'Bada Stealer' Malware
First seen 12 Feb 2026, 21:16 UTC
•

•35.0
Export
Article Content
Browse articles
A malicious NPM package named 'duer-js' has been identified, distributing 'Bada Stealer' malware. This package, published by 'luizaearlyx', poses risks to Windows and Discord users, despite only 528 downloads. Security experts are warning developers about its sophisticated attack methods.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2026-02-12
Malicious 'duer-js' package discovered on NPM
2026-02-12
Security experts issue warnings about the malware
More articles in this cluster
Continue Reading
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
North Korean Hackers Utilize EtherHiding for Cryptocurrency Theft
Webworm APT Expands Operations to Europe with New Backdoors
TeamPCP Compromises Microsoft DurableTask and GitHub Actions in Supply Chain Attack
PATCHCORD Malware Targets Afghan Telecom and South Asian Infrastructure
North Korean ClickFake Campaign Targets Web3 Professionals with RATs