Tracked campaign · npm
Clob dropper
Three npm packages from publisher devcarron shipping identical postinstall droppers fetching a Windows PE via IPFS within a 4-minute burst.
2,334 packages attributednpm ecosystempkgradar source
Attribution basis
- shared malware fingerprint
- OSV advisory cluster
- shared publisher account
Sample attributed packages
@achuthanmukundan00/synax@0.3.0-beta.1@achuthanmukundan00/synax@0.3.0-betanuxs-capsule@0.5.59nuxs-capsule@0.5.58@mintplex-labs/tab-complete@1.0.3@wacrot/infra-data-kit@2.1.4nuxs-capsule@0.5.56@exellix/graph-composer@2.7.9nuxs-capsule@0.5.55@wacrot/infra-data-kit@2.1.2nuxs-capsule@0.5.54@bike4mind/cli@0.0.0-feat-opti-graph-partitioning-20260612213320nuxs-capsule@0.5.53nuxs-capsule@0.5.52vfx-web-sdk@2.0.12vfx-web-sdk@2.0.13vfx-web-sdk@2.0.14vfx-web-sdk@3.0.0nuxs-capsule@0.5.51index-ulid@3.0.3nuxs-capsule@0.5.49nuxs-capsule@0.5.50nuxs-capsule@0.5.48@amazon-devices/react-native-fast-image@3.0.7@amazon-devices/react-native-fast-image@3.0.12-rn-83nuxs-capsule@0.5.47nuxs-capsule@0.5.46nuxs-capsule@0.5.44nuxs-capsule@0.5.45@mintplex-labs/tab-complete@1.0.2