Security researchers reported a coordinated campaign targeting high-impact Node.js and npm maintainers through social engineering, with the activity described as focused on influential open-source developers whose accounts or packages could provide broad downstream access. Public reporting tied the operation to attempts to compromise trusted maintainers in the JavaScript ecosystem, including references to widely used projects such as Axios, raising concern over software supply chain exposure if attacker access were obtained.
Separate reporting also tracked an OtterCookie infostealer campaign operating across npm, linking the malware activity to the same broader threat context and associating it with DPRK-aligned tradecraft. The combined reporting indicates an effort to use maintainer targeting and malicious npm activity to steal credentials, compromise developer environments, and potentially abuse trusted package distribution channels for follow-on supply chain attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A JFrog research report highlighted npm malware masquerading as Rollup polyfills and framed it as a software supply-chain threat in the npm ecosystem. The referenced post explicitly associated the activity with Lazarus, but did not provide package names, indicators, or victim details in the source content.
A Panther publication reported on an OtterCookie infostealer campaign affecting the npm ecosystem. The reference links the activity to ContagiousTrader and DPRK-related context, but the provided content does not include further technical details or confirmed victim disclosures.
A Socket report described attackers targeting high-impact Node.js maintainers in a coordinated social engineering campaign. The reference associates the activity with the npm ecosystem and influential open-source maintainers, but provides no additional victim or technical details in the source content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
bsky.app
Open sourcebsky.app
Open sourcebsky.app
Open sourcebsky.app
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.