Published: · Region: Global · Category: cyber

Malicious npm Packages and macOS ‘ClickFix’ Stealer Expose New Supply-Chain Risk for Crypto and Credentials

Nearly 800 malicious npm packages seeding a cross-platform infostealer and a new macOS ‘ClickFix’ attack that drains crypto wallets point to a dangerous convergence of software supply-chain abuse and targeted credential theft. Developers, crypto holders, and corporate IT teams face a threat that jumps from open-source code to personal devices with a single install or pasted command.

The open-source tools that power modern software—and the convenience shortcuts that many users rely on—are being turned into quiet entry points for credential theft and drained crypto wallets. Security researchers have identified nearly 800 malicious packages uploaded to the npm registry, the JavaScript ecosystem’s central repository, delivering a cross-platform remote access trojan (RAT) and infostealer. The campaign targets development environments on Windows, macOS, and Linux, using a loader dubbed WEL1DROPPER to fetch platform-specific payloads. If HTTPS connections fail, the malware can reportedly fall back to DNS TXT records to receive its instructions, a design that significantly complicates detection and blocking. In parallel, investigators have detailed a separate macOS-focused campaign dubbed…

Pro features include

  • 60+ analytical tools across markets and intelligence
  • Custom alerts, watchlists, and AOI monitoring
  • Daily Pro brief at 6 PM ET — 12 hours before free tier
  • Conflict deep dives and premium research products