TL;DR Sonatype Research Labs identified six npm packages delivering the same malicious payload: three hijacked legitimate packages and three additional malicious packages, tracked as sonatype-2026-005899 and sonatype-2026-005901 . The malware uses the same Ethereum wallet addr ess identified by OpenSourceMalware in a ctivity attributed to the DPRK-linked Contagious Interview campaign, using the “NullReceiver” technique to locate infrastructure hosting additional JavaScript payloads. Organizations that installed the affected versions should remove them and investigate the impacted environment f
Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads
calendar_today
August 10, 2026
person
research@sonatype.com (Sonatype Research Team)
domain
sonatype