isc.sans.edu 5/22/2026, 7:11:03 AM · external

Node.js NPM Stealer Targets Windows, macOS, Linux with C2 Ties

Node.js NPM Stealer Targets Windows, macOS, Linux with C2 Ties
CyberSIXT Evidence Panel Source marked as original reporting

THE report, authored by Xavier Mertens, discusses a newly discovered Node.js malware classified as a cross-platform NPM stealer targeting Windows (WSL), macOS, and Linux. The malicious code is obfuscated but includes embedded plain-text payloads. It features a browser credential stealer supporting various browsers, a recursive file exfiltration scanner for sensitive files, and a WebSocket connection for communication with a command and control (C2) server known for DPRK activities.

Notably, data exfiltration is conducted via specific ports (8085, 8086, 8087), and the malware employs various techniques to facilitate its operations while communicating securely with its C2 server.

View full article

Article by CyberSIXT