Skip to content
Malicious npm Packages Target Developer Credentials Across Multiple Operating Systems

Malicious npm Packages Target Developer Credentials Across Multiple Operating Systems

First seen 2 Nov 2025, 16:14 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A series of malicious npm packages have been identified that target developer credentials on Windows, macOS, and Linux systems. These packages exploit system keyrings and bypass application-level security to steal decrypted credentials. Affected users are advised to revoke their credentials and rebuild their environments to mitigate the impact.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 213d ago How this analysis works

More articles in this cluster (2)