Typosquatted npm Packages Expose Developer Credentials

29 Oct 2025

In July 2025, npm malware infiltrated developer environments by targeting credentials across Windows, Linux, and macOS systems. Researchers discovered ten malicious packages on npm that delivered malware to steal sensitive information.

How the Threat Unfolded

Security researchers at Socket identified that at least ten typosquatted npm packages were uploaded in early July 2025. These packages, named deezcord.js, dezcord.js, dizcordjs, among others, were designed to steal credentials from system keyrings, browsers, and authentication services. The malware was downloaded approximately 9,900 times before removal.

The malware employed sophisticated techniques including four layers of obfuscation, a fake CAPTCHA, and victim fingerprinting via IP. It also installed a 24MB PyInstaller-packaged infostealer.

Potential Impact on Security

The malware posed a significant threat by bypassing application-level security and accessing decrypted credentials. It targeted critical information such as email accounts, cloud storage passwords, SSH keys, and database connection strings, posing risks of unauthorized access and data breaches.

Security analyst Kush Pandya highlighted the potential for extensive damage due to access to internal networks.

Recommended Mitigation Steps

To mitigate risks, researchers recommend immediate actions: disconnect affected systems, revoke exposed credentials like SSH keys and cloud provider tokens, wipe and rebuild infected systems, change all passwords, audit npm dependencies and lockfiles, review logs for unusual activity, and enable multi-factor authentication.

These measures aim to protect developers and organizations from further security vulnerabilities and potential breaches.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6759818
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1437151
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
585084
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
464291
downloads

News and reviews for Desktop Windows

Hello Sunshine Revealed at PC Gaming Show, Playtest Opens

Hello Sunshine debuts at the PC Gaming Show. Developed by Red Thread Games, set for 2026 release with playtest sign-ups now open.

Read more

PC Gaming Show: Most Wanted 2025 Highlights Top Games

The PC Gaming Show: Most Wanted 2025 unveils premieres and Council's top 25, featuring GTA 6 and Slay the Spire 2.

Read more

Prime Gaming Offers 14 Free Games in December

Prime Gaming presents 14 free December games, highlighting Deus Ex and retro D&D titles. Games remain after subscription ends.

Read more

PC Gaming Show Reveals 86 Titles for 2025

The PC Gaming Show unveils 86 game titles, including major franchises, set for release in 2025.

Read more

Kill Joy Game Announced for PC: A Unique System-driven Experience

Kill Joy, a unique systems-driven exploration game, announced for PC. Players escape deceptive worlds by making creatures cry.

Read more

Epic Games Store Offers Free Games: Limited Time Access

Epic Games Store presents Free Games this December: The Darkside Detective and Jackbox Party Pack 4 for one week.

Read more

Sony Partners with Bad Robot for New Co-op Shooter

Sony teams up with Bad Robot Games for a co-op shooter on PS5 & PC, led by Mike Booth.

Read more

Microsoft Patches Windows LNK Zero-Day Exploit

Microsoft addressed a critical Windows LNK vulnerability in 2025-10; impact are worldwide malware risks.

Read more

Helldivers 2 Install Size Reduced to 23GB in Beta

Arrowhead optimizes Helldivers 2 on PC, reducing installation size from 154GB to 23GB. New beta shows improved load speeds and space efficiency.

Read more

Prologue Expands with Three DLCs but No Wildlife

Prologue creator Brendan Greene confirms three new DLCs, focusing on game depth but ruling out animal additions.

Read more