Typosquatted npm Packages Expose Developer Credentials

29 Oct 2025

In July 2025, npm malware infiltrated developer environments by targeting credentials across Windows, Linux, and macOS systems. Researchers discovered ten malicious packages on npm that delivered malware to steal sensitive information.

How the Threat Unfolded

Security researchers at Socket identified that at least ten typosquatted npm packages were uploaded in early July 2025. These packages, named deezcord.js, dezcord.js, dizcordjs, among others, were designed to steal credentials from system keyrings, browsers, and authentication services. The malware was downloaded approximately 9,900 times before removal.

The malware employed sophisticated techniques including four layers of obfuscation, a fake CAPTCHA, and victim fingerprinting via IP. It also installed a 24MB PyInstaller-packaged infostealer.

Potential Impact on Security

The malware posed a significant threat by bypassing application-level security and accessing decrypted credentials. It targeted critical information such as email accounts, cloud storage passwords, SSH keys, and database connection strings, posing risks of unauthorized access and data breaches.

Security analyst Kush Pandya highlighted the potential for extensive damage due to access to internal networks.

Recommended Mitigation Steps

To mitigate risks, researchers recommend immediate actions: disconnect affected systems, revoke exposed credentials like SSH keys and cloud provider tokens, wipe and rebuild infected systems, change all passwords, audit npm dependencies and lockfiles, review logs for unusual activity, and enable multi-factor authentication.

These measures aim to protect developers and organizations from further security vulnerabilities and potential breaches.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7102931
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1572720
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
676031
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
481979
downloads

News and reviews for Desktop Windows

Windows Installer Cleanup: Safely Free Up Disk Space

Learn how to manage the C:\Windows\Installer cache. Safely free disk space without breaking updates or repairs.

Read more

Top PC Games to Watch in 2026: Key Releases and Changes

Explore the most anticipated PC games for 2026 featuring unique strategies and innovative design shifts.

Read more

Optimization Review: 2025's Worst-Performing PC Games

How optimization issues impacted 2025's PC game releases, with many titles facing major performance challenges.

Read more

AI Games: Developer Skeptical of AI-Led Creation

Adrian Chmielarz doubts AI games as feasible soon due to hardware limits and creative needs.

Read more

CD Projekt Sells GOG to Co-Founder for $25.2M

CD Projekt sells GOG back to co-founder Michal Kicinski for $25.2M to refocus on game development.

Read more

Microsoft Embeds AI Agents in Windows for Major 2025 Update

Microsoft to integrate AI agents into Windows by 2025, enhancing task management and AI ecosystem.

Read more

pingPong Launches: AIM-Style Chat App with Retro Appeal

A 15-year-old's pingPong app channels retro AIM style, merging nostalgia with modern devices.

Read more

Microsoft Alters Appxsvc to Auto-Start in Windows 11

Microsoft updates Appxsvc for Windows 11 and Windows Server 2025, auto-starting the service from boot to improve app reliability.

Read more

Ubisoft Restores Rainbow Six Siege After Massive Hack

Ubisoft has recovered Rainbow Six Siege's servers post-hack, rolling back unauthorized item giveaways.

Read more

Top Cozy Games of 2025: Diverse Picks Lead the Pack

In 2025, cozy games expanded their audience with diverse offerings. Discover the top cozy games and their unique appeal.

Read more