846 malicious npm packages, one loader, and a payload chosen to match your operating system
2026-08-11Security
Sonatype tracked a campaign flooding npm with 846 packages carrying a multi-stage JavaScript loader. It fingerprints the operating system, fetches a matching payload, and on Windows patches security functions before establishing persistence through a scheduled task.