Security researchers reported multiple software supply-chain threats in public package registries where attacker-controlled libraries masquerade as legitimate utilities but install Windows infostealers. On NPM, a package named duer-js (publisher luizaearlyx) posed as a console visibility tool and delivered a multi-stage stealer self-identified as Bada Stealer; analysis attributed to JFrog Security Research described heavy obfuscation, persistence that can survive simple uninstall attempts, and follow-on payload delivery targeting Discord by hijacking the desktop client’s startup/injection path to continuously steal data when Discord runs.
Separately, Safety’s research team documented “ExtraZip”, a campaign of 14 trojanized PyPI packages impersonating ZIP utilities or mail-sending libraries that deploy a staged infostealer focused on Telegram Desktop session files, exfiltrating them via an attacker-controlled Telegram bot. The report described 32 layers of obfuscation and provided an inventory of package names (e.g., extrazip, minizip, ziphash, and multiple smt*lib lookalikes) and a timeline of publishing activity across late 2025 through early 2026, indicating sustained, iterative attempts to seed malicious dependencies into developer environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
JFrog Security Research's analysis of the 'duer-js' package was publicly reported, highlighting that uninstalling the NPM package alone would not remove the threat because it established persistence through Discord. The report also described exfiltration via a Discord webhook and a backup Gofile channel.
A malicious NPM package named 'duer-js,' published by the user 'luizaearlyx,' was made available while posing as a console visibility tool. When installed, it deployed a multi-stage stealer that persisted through Discord startup injection and stole data from Discord, browsers, crypto wallets, Telegram, and Steam.
Safety published research on the ExtraZip campaign, detailing 14 trojanized PyPI packages, a 32-layer obfuscation chain, Telegram-focused data theft, and related indicators of compromise such as package names, hashes, C2 endpoints, and Telegram bot details.
The ExtraZip operation continued to publish trojanized Python packages over subsequent waves, ultimately totaling 14 malicious packages. On Windows, the packages fetched additional payloads, used heavily obfuscated multi-stage execution, and exfiltrated Telegram Desktop session data via the Telegram Bot API.
The ExtraZip supply-chain campaign started releasing malicious PyPI packages masquerading as ZIP utilities and email-related libraries in multiple waves. Safety said the activity began in late November 2025 and used several author aliases, with necr.email@example.com tied to most packages.
3 references tracked. Mallory keeps watching after this page renders.
npmjs.com
Open sourcecybersecuritynews.com
Open sourcegetsafety.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.