Security researchers at Datadog identified 17 npm packages, across 23 releases, that were trojanized to deliver the Vidar infostealer malware to Windows systems. These packages, which masqueraded as legitimate SDKs, Telegram bot helpers, icon libraries, and forks of popular projects, executed the malware through a postinstall script. The campaign, attributed to the threat activity cluster MUT-4831, marks the first public disclosure of Vidar being distributed through npm packages. The malicious packages provided real functionality to avoid suspicion and were available on the npm registry for approximately two weeks before being removed, during which time they were downloaded at least 2,240 times, though many downloads were likely automated.
The threat actors behind the campaign used multiple npm accounts, which have since been banned, to distribute the malware. The incident highlights the ongoing risk of malicious code being uploaded to open source repositories and the challenges faced by developers and CISOs in ensuring the security of dependencies. Datadog's GuardDog tool played a key role in detecting the suspicious packages, and the discovery underscores the need for continuous monitoring and improved security measures within open source ecosystems to prevent similar supply chain attacks.

Trace attribution and downstream blast radius.
3 events from the most recent confirmed update back to the earliest known activity.
Datadog Security researchers discovered the malicious npm packages and documented the campaign as MUT-4831. By the time of reporting, the 17 packages had been removed from npm.
The trojanized packages stayed on npm for about two weeks and were downloaded at least 2,240 times while exposed to developers. This distribution window enabled the Vidar malware campaign to reach victims through the open source supply chain.
Attackers uploaded 17 trojanized npm packages masquerading as legitimate libraries, including Telegram bot helpers, icon libraries, and forks of popular projects. The packages used postinstall scripts to target Windows systems with the Vidar infostealer.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 25 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecuritylabs.datadoghq.com
Open sourcecsoonline.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.