# Malicious npm Packages and macOS ‘ClickFix’ Stealer Expose New Supply-Chain Risk for Crypto and Credentials

*Friday, August 7, 2026 at 8:05 PM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-08-07T20:05:59.591Z (3h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/13502.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Nearly 800 malicious npm packages seeding a cross-platform infostealer and a new macOS ‘ClickFix’ attack that drains crypto wallets point to a dangerous convergence of software supply-chain abuse and targeted credential theft. Developers, crypto holders, and corporate IT teams face a threat that jumps from open-source code to personal devices with a single install or pasted command.

The open-source tools that power modern software—and the convenience shortcuts that many users rely on—are being turned into quiet entry points for credential theft and drained crypto wallets. Security researchers have identified nearly 800 malicious packages uploaded to the npm registry, the JavaScript ecosystem’s central repository, delivering a cross-platform remote access trojan (RAT) and infostealer. The campaign targets development environments on Windows, macOS, and Linux, using a loader dubbed WEL1DROPPER to fetch platform-specific payloads. If HTTPS connections fail, the malware can reportedly fall back to DNS TXT records to receive its instructions, a design that significantly complicates detection and blocking. In parallel, investigators have detailed a separate macOS-focused campaign dubbed…

---

*Full article available with Hamer Intel Pro — https://hamerintel.com/pricing*
