Skip to content
ThreatCluster

Over 15 Malicious npm Packages Delivering Vidar Malware on Windows Systems

First seen 7 Nov 2025, 12:54 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

More than 15 weaponized npm packages have been identified that exploit Windows systems to deploy Vidar malware. These malicious packages target users by masquerading as legitimate software, potentially compromising sensitive data. The ongoing threat affects a wide range of Windows users and organizations relying on npm for package management.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 213d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track Vidar in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed