Supply chain

MUT-8694 npm and PyPI Malicious Package Campaign

πŸ“… 2024-10-10 🏒 npm registry; PyPI 🦠 Blank Grabber infostealer; Skuld Stealer
Primary Source β†—

Incident Details

Datadog Security Labs identified a coordinated supply chain attack campaign (tracked as MUT-8694) active from at least October 10, 2024, targeting both the npm and PyPI package ecosystems β€” the first observed simultaneous campaign across both registries by a single threat actor. The campaign used 42 malicious PyPI packages and 18 npm packages, most typosquatting legitimate names. Packages predominantly targeted Roblox developers (stealing Roblox cookies, browser passwords, crypto wallets, Telegram sessions). Malware payloads included Blank Grabber and Skuld Stealer (open source infostealers). Targeted Windows users. The campaign highlighted the risk of cross-ecosystem coordinated supply chain attacks by a single threat actor.

Technical Details

Initial Attack Vector
Typosquatting: malicious packages uploaded to npm and PyPI mimicking legitimate library names to trick developers into installing them
Vendor / Product
npm registry; PyPI
Software Package
larpexodus (PyPI); various typosquatted Roblox-related npm packages (42 PyPI + 18 npm packages total)
Malware Family
Blank Grabber infostealer; Skuld Stealer

Timeline

  1. 2024-10-10 Breach occurred
  2. 2024-10-01 Publicly disclosed