Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages

a3e2ffb440b779d30da3ff282affd649731088e8570df7b1aa72742d995b782c

TLP:CLEAR
Active

SHA-256 Hash

Description

A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages
Pattern Type
STIX
Confidence
75%
Valid From
Aug 10, 2026 12:01
Total Sightings
0
Added
Aug 10, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of a3e2ffb440b779d30da3ff282affd649731088e8570df7b1aa72742d995b782c

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.