Skip to content
ThreatCluster

New npm Malware Campaign Targets Users Based on Visitor Type

First seen 2 Dec 2025, 18:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A new malware campaign targeting npm users has been identified, which determines if a visitor is a potential victim or a researcher before initiating an infection. This sophisticated approach aims to evade detection and maximize the effectiveness of the malware. Users of npm, a popular package manager for JavaScript, are particularly at risk from this campaign.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)