Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages
Recommendation:
• If you identify that any of these 800+ NPM packages has been installed in your environment, appears in a lockfile, software bill of materials, package-manager cache, build log, or deployed application, do not assume that removing the dependency is sufficient.
• Determine whether the package was ever imported. Review DNS logs for TXT lookups under wel1.ru, proxy logs for all eight Cloudflare Workers hosts, and endpoint telemetry for the dropped-file and process patterns above.
• On macOS, specifically hunt for the fake runtime executable and LaunchAgent. Because the final beacon remains unavailable for analysis, a confirmed execution should be handled as a potential host compromise.
• Rotate credentials accessible to affected developer workstations or CI runners, including npm tokens, GitHub tokens, cloud credentials, signing keys, and deployment secrets. Rebuild affected systems from a known-good state where appropriate.
https://opensourcemalware.com/blog/russian-ai-slopsquatting-npm-campaign
Post #401
616