Skip to content
npm Packages Compromise Developer Credentials Across Multiple Platforms

npm Packages Compromise Developer Credentials Across Multiple Platforms

First seen 2 Dec 2025, 18:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Malware targeting npm packages has been identified, compromising developer credentials on Windows, Linux, and macOS. The malware bypasses app-level security by targeting system keyrings, leading to the theft of decrypted credentials. Affected users are advised to revoke their credentials and rebuild their environments.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)