Malicious npm packages evade install-script defenses at runtime

2026-09-20T19:23:22Z•85ac8aa1a5e8bf786a2277c33cecb22be5b0ae0ffba259db4eed12b1a599630e
AI-securityAndroid-malwareCheck-PointGitHub-abuseNorth-KoreaWaterPlumbrowser-agentscryptocurrency-theftcybercrimedata-breachinfostealermalicious-browser-extensionsmalwarenpmransomwareroot-code-executionsandbox-escapesupply-chain-securityvulnerability

What happened

A BleepingComputer security-news feed covering active malware campaigns, software vulnerabilities, AI-agent and sandbox security research, data breaches, ransomware activity, and defensive product updates. Notable items include runtime-based npm supply-chain malware, OpenAI Codex sandbox escapes, malicious extensions hijacking AI browser agents, North Korean WaterPlum infections and cryptocurrency theft, a Gyazo breach affecting 23.6 million records, Rapuncel infostealer distribution through fake GitHub repositories, a critical Check Point root-code-execution flaw, and Android RatHat malware.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
85ac8aa1a5e8bf786a2277c33cecb22be5b0ae0ffba259db4eed12b1a599630e
Enrichment time
2026-09-20T19:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Malicious npm packages evade install-script defenses at runtime · Baitaphish