Habr•July 31, 2026•🇷🇺Translated from Russian

Malicious npm Packages Deploy Multi-Stage Trojan with Embedded GitLab Keys

Researchers at Positive Technologies have detailed a months-long campaign in which an attacker uploaded trojanized packages to the npm registry from five accounts: alex05255, mdrafiqulislamrabby, b.w1001, abdev8773 and mollspotwood54400.

The malicious packages are: svg-fetcher, tradepilot, polytrade, polymarket-kit, react-svg-chunk, gamified-trading-system, font-huge, font-hub, mdb-vite, router-processor and route-processor.

The first-stage code is lightly obfuscated and contains verbose explanatory comments that reveal its logic. It assembles the command-and-control address from multiple string constants and requests the next stage from http://svganchordev.net/icons/<token>, sending the value logo in the bearrtoken header.

Known stage versions are 106, 107, 108 and 116. The second stage is delivered as a single heavily obfuscated JavaScript line that, once formatted, collects the current username, computer name and operating-system details before opening a WebSocket connection to receive further commands.

Stages 106 and 116 contain an additional surprise: hardcoded public and private keys for a private GitLab instance hosted in the attacker’s own infrastructure. Although the keys cannot be used against external systems, their presence indicates that the actor maintains a CI/CD pipeline to automate obfuscation and publication of new stages.

Positive Technologies has reported all malicious packages to npm administrators and recommends that development teams integrate automated feeds from PT Fusion to detect supply-chain threats before they reach production environments.

Related articles

AntiMalware•Supply Chain & Open Source

PhantomSub Campaign Deploys 101 Malicious npm Packages to Hijack WhatsApp Accounts for Unauthorized Channel Subscriptions

Researchers at OX Security uncovered 101 malicious npm packages tied to the PhantomSub campaign that abuse connected WhatsApp accounts to subscribe users to promotional channels without consent. The packages disguise themselves as modified versions of the open-source Baileys library used for WhatsApp automation. Attackers rely on authenticated sessions rather than simple package installation, allowing them to control subscriptions through lists stored on GitHub, in plaintext, or as encoded identifiers. The packages have accumulated roughly 490,000 downloads, including 116,000 in the past 30 days, though the exact number of compromised accounts remains unknown. As of 28 September, npm had removed only 16 of the identified packages. The operation ultimately benefits channels selling bots, game resources, accounts, and promotion services by inflating subscriber counts while disabling notifications to hide the activity.

Habr•Supply Chain & Open Source

AI Model Hallucinations Fuel Slopsquatting Attacks on PyPI and npm Registries

Researchers identified 139 package names consistently hallucinated by five different AI models across Python and JavaScript ecosystems. Seven of these names are already registered on PyPI and npm, including one previously used to distribute malware. The attack vector, termed slopsquatting, allows attackers to register AI-suggested package names and execute code with developer privileges during installation. One package, metro-evaluator, contained malicious code removed by npm in December 2025, while another empty package css-color-stop began receiving downloads after the list was published. Real projects such as odf and lusid now occupy names that AI models recommend, causing developers to install unrelated software. Studies show hallucination rates between 4.62% and 21.7% depending on the model, with commercial models performing better than open-source ones. The findings highlight risks when AI coding agents execute dependency installation commands without human verification.

Habr•Supply Chain & Open Source

Sapper Revives Minefield to Deliver Accurate SBOM-Based Vulnerability Impact Reports for Cyber Resilience Act Compliance

Developer Perruer has forked the archived BitBom project Minefield into a new open-source tool called Sapper, fixing critical bugs in dependency graph construction and vulnerability matching. The original Minefield used roaring bitmaps and Tarjan's algorithm to build transitive dependency caches from SBOMs in O(n + m) time, but it incorrectly interpreted SPDX edge directions from protobom 0.6, creating false cycles and massively inflating dependent package counts. Additional fixes addressed SQLite memory database pooling issues, OSV range sorting errors with Go pseudo-versions and ECOSYSTEM ecosystems, and slow OSV ingestion by adding a package name index. Sapper now produces prioritized reports using CISA KEV and EPSS scores, showing exact shortest paths from vulnerable packages to root products while respecting OpenVEX statements. The tool maintains full air-gapped operation and supports CycloneDX 1.3–1.7 and SPDX 2.x formats. These improvements directly help organizations meet the 24-hour notification requirements under the EU Cyber Resilience Act for actively exploited vulnerabilities.

BoletimSec•Supply Chain & Open Source

Fake Terraform Providers on HashiCorp Registry Distribute Go Malware to Developers

Cybersecurity researchers have identified Go-based malware distributed through two fake Terraform providers and two Go modules hosted on the official HashiCorp registry. The providers gocommunity-io/dockerd and kreuzwenker/docker, along with modules gocommunity.io/orderedbtree and gogets.dev/btreex, impersonate legitimate projects and represent the first documented case of malicious code being delivered via the HashiCorp registry. Attackers approach developers on LinkedIn, Facebook, and job forums using fake Web3 company profiles, then supply seemingly harmless repositories whose malicious behavior is triggered through npm or PyPI dependencies. Once executed, the malware collects hardware attributes, operating system data, hostname, and node availability before sending the information to attacker infrastructure. Command and control relies on a Slack channel polled every ten seconds and encrypted commands read from Sepolia testnet Ethereum smart contracts every three seconds, with each infected client using ephemeral key pairs for targeted delivery. The code matches the Graphalgo campaign previously documented by ReversingLabs and attributed to North Korean actors.