npm Packages Compromise Developer Credentials Across Multiple Platforms

npm Packages Compromise Developer Credentials Across Multiple Platforms

First seen 2 Dec 2025, 18:33 UTC ThehackernewsTechradar 11.5

Article Content

Browse articles
ThreatCluster

Malware targeting npm packages has been identified, compromising developer credentials on Windows, Linux, and macOS. The malware bypasses app-level security by targeting system keyrings, leading to the theft of decrypted credentials. Affected users are advised to revoke their credentials and rebuild their environments.