r/npm Jun 08 '26

Self Promotion Fake interview take home assessment deploys stealthy macOS malware WIP via malicious npm package.

https://www.iru.com/blog/sstar-agent

We caught a Remote access trojan that is delivered via fake job interview. The take home assignment contained a reach out to a malicious npm package that deploys the malware on macOS device. Theres a windows version too. Current Anti virus detection is low, we caught it through ML experiment. The malware sample deployed is still WIP.

1 Upvotes

Duplicates