TGViewer
SITREP - Independent OSINT Channel SITREP - Independent OSINT Channel @sitreports · 23K subscribers
Post #39535 305
🔍 Eight npm packages used to push Overlord RAT and stealer

Eight malicious npm packages were downloaded 40,767 times before detection, delivering Overlord RAT and an information stealer through the software supply chain. The activity targeted developers and downstream environments that installed the packages from the JavaScript ecosystem.

The case reinforces how low-friction package publication can convert routine dependency pulls into initial access. For defenders, the key issue is exposure propagation: one compromised package can extend beyond a single workstation into build systems, secrets, and any product pipeline that consumed it.

🛰️ Open sources - closed narratives
@sitreports
More from @sitreports
  1. Oct 9, 2026🔍 FBI details China-linked email access portal The FBI says China-linked hackers operated…
  2. Oct 9, 2026📡 Ransomware disrupts Japan’s IDCF Cloud IDC Frontier says a ransomware attack hit its ID…
  3. Oct 9, 2026🔍 FakeGit reactivates at scale on GitHub FakeGit has resumed activity with 17,610 malicio…
  4. Oct 9, 2026🔍 Cisco flags five critical NX-OS flaws on Nexus switches Cisco has issued advisories for…
  5. Oct 9, 2026🔍 Low-cost Android phones found shipping with firmware-level malware Bitdefender’s Midnig…
  6. Oct 9, 2026🔍 UAC-0099 deploys ASHVEIN RAT against Ukrainian government staff UAC-0099 is targeting U…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →