Malicious npm packages evade install-script defenses at runtime

2026-09-21T07:23:22Z•0ef74d57e7a7c2389926ee13dfd0f81d23189210aa30a4d3793d2b0a7002c431
AI-securityAndroid-malwareGitHub-abuseNorth-KoreaRapuncelRatHatWaterPlumbrowser-agent-hijackingcritical-vulnerabilitycryptocurrency-theftdata-breachinfostealermalicious-browser-extensionmalwarenpmransomwareroot-privilege-escalationruntime-code-executionsandbox-escapesoftware-supply-chain

What happened

A BleepingComputer security-news feed covering active malware campaigns, software supply-chain attacks, AI-agent sandbox escapes and browser-agent hijacking, major data breaches, state-sponsored cybercrime, ransomware activity, and critical product vulnerabilities. Notable items include the WaterPlum North Korean campaign infecting at least 30,000 devices, a Gyazo breach exposing 23.6 million records, runtime-based npm malware, Rapuncel infostealer distribution through fake GitHub repositories, RatHat Android malware, and a Check Point flaw enabling root-level code execution.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
0ef74d57e7a7c2389926ee13dfd0f81d23189210aa30a4d3793d2b0a7002c431
Enrichment time
2026-09-21T07:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.