Typosquatted npm Packages Expose Developer Credentials

29 Oct 2025

In July 2025, npm malware infiltrated developer environments by targeting credentials across Windows, Linux, and macOS systems. Researchers discovered ten malicious packages on npm that delivered malware to steal sensitive information.

How the Threat Unfolded

Security researchers at Socket identified that at least ten typosquatted npm packages were uploaded in early July 2025. These packages, named deezcord.js, dezcord.js, dizcordjs, among others, were designed to steal credentials from system keyrings, browsers, and authentication services. The malware was downloaded approximately 9,900 times before removal.

The malware employed sophisticated techniques including four layers of obfuscation, a fake CAPTCHA, and victim fingerprinting via IP. It also installed a 24MB PyInstaller-packaged infostealer.

Potential Impact on Security

The malware posed a significant threat by bypassing application-level security and accessing decrypted credentials. It targeted critical information such as email accounts, cloud storage passwords, SSH keys, and database connection strings, posing risks of unauthorized access and data breaches.

Security analyst Kush Pandya highlighted the potential for extensive damage due to access to internal networks.

Recommended Mitigation Steps

To mitigate risks, researchers recommend immediate actions: disconnect affected systems, revoke exposed credentials like SSH keys and cloud provider tokens, wipe and rebuild infected systems, change all passwords, audit npm dependencies and lockfiles, review logs for unusual activity, and enable multi-factor authentication.

These measures aim to protect developers and organizations from further security vulnerabilities and potential breaches.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6287384
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1232923
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
484011
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
451981
downloads

News and reviews for Desktop Windows

Arc Raiders Preload Unavailable on Epic Games Store

Arc Raiders preload is disabled on Epic Games Store due to an issue; download starts 2023-10-30.

Read more

Typosquatted npm Packages Expose Developer Credentials

In July 2025, npm malware targeted developer credentials globally, risking data breaches.

Read more

Arc Raiders Launch: New Challenges and Rewards Await

Arc Raiders launch brings new challenges and map dynamics. Players can opt for strategic wipes, gaining meta-rewards.

Read more

Arc Raiders Offers Casual Extraction Shooter Experience

Arc Raiders by Embark Studios provides a less punishing extraction shooter with PvEvP gameplay and unique robo threats.

Read more

Office 2019 Available at 86% Discount for Windows Users

Get Office 2019 for Windows at $29.97, 86% off the regular price. Includes a lifetime license for essential apps with no recurring fees.

Read more

Linux Gains Gaming Compatibility, Challenges Remain

Linux gaming on the rise with 90% of Windows games now supported. Anti-cheat titles still pose a hurdle for SteamOS users.

Read more

Launch Office 2024: Lifetime License for $179.99

Microsoft offers Office 2024 with a one-time payment of $179.99, including Word, Excel, and more for Mac and PC, in a limited-time deal.

Read more

Helldivers 2 Targets Smaller File Size by Dropping HDD Support

Arrowhead Game Studios plans to reduce Helldivers 2's file size by ending HDD support on PCs, potentially streamlining updates.

Read more

Launch of GOG Sale Features 4,000 PC Game Discounts

GOG Sale offers discounts on 4,000 PC games from 2023-10-28 to 2023-11-04, featuring modern and classic titles.

Read more

Darkwood 2 Announced: Sequel from Ice-Pick Lodge

Darkwood 2 announced at Xbox Showcase, developed by Ice-Pick Lodge, featuring Aral Sea setting with no quest markers.

Read more