Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages

e2650e9aa2f924433ba422857b22ee7c5996b5ad306f3f903283f6a13e248935

TLP:CLEAR
Active

SHA-256 Hash

Description

A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages
Pattern Type
STIX
Confidence
75%
Valid From
Aug 10, 2026 12:01
Total Sightings
0
Added
Aug 10, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of e2650e9aa2f924433ba422857b22ee7c5996b5ad306f3f903283f6a13e248935

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.