
Threat Intelligence11 min read
Inside a 37-Package npm Typosquatting Campaign Targeting Windows and WSL
OpenHack correlated 37 npm typosquats carrying the same install-time dropper, decoded its XOR-obfuscated configuration, and traced a Windows and WSL infostealer chain from npm postinstall to credential exfiltration.
Ananay Arora·