Fake 'distube-config' npm package drops Windows info-stealing malware

Fake 'distube-config' npm package drops Windows info-stealing malware

Sonatype has identified two npm packages distube-config and discordyt that typosquat open source packages like Discord modules, in an attempt to infect Windows users with a Trojan. Our security researcher, Juan Aguirre, who analyzed the malware shares some insights.

Article Link: Fake 'distube-config' npm package drops Windows info-stealing malware