Thehackernews
Malicious npm Packages Target Developer Credentials Across Multiple Operating Systems
First seen 2 Nov 2025, 16:14 UTC
•
•19.1
Export
Article Content
Browse articles
A series of malicious npm packages have been identified that target developer credentials on Windows, macOS, and Linux systems. These packages exploit system keyrings and bypass application-level security to steal decrypted credentials. Affected users are advised to revoke their credentials and rebuild their environments to mitigate the impact.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Google Addresses Eighth Chrome Zero-Day Vulnerability in 2025
China-linked Cyber Group Expands Targeting to Southeastern Europe
China-Nexus APT UAT-7290 Targets South Asia Telecoms in Cyber Espionage Campaign
China-linked UAT-7290 Targets Telcos in Cyberespionage Campaign
UAT-7290 Cyber Espionage Targets South Asian Telecoms
New WebKit Zero-Day CVE-2025-14174 Discovered and Exploited