Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages
A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.
AI Analysis
Technical Summary
This campaign involves a threat actor publishing over 700 malicious NPM packages using AI-generated typo-squatting names to trick developers into importing them. The malicious packages deploy a cross-platform RAT and infostealer that execute immediately upon import via require(), bypassing the need for install scripts. Payload delivery rotates through three Cloudflare Workers hosts with a DNS TXT record fallback under the domain wel1.ru. The macOS payload achieves persistence through LaunchAgents and downloads additional beacons, while the Linux payload appears to deliver a Sliver implant. The campaign shares tradecraft with the Moika malware operation, including targeting Russian financial institutions, fake telemetry for camouflage, and similar kill switch mechanisms. The malware includes anti-analysis features that detect debuggers, virtualization environments, and packet capture tools to evade detection and analysis.
Potential Impact
The malicious NPM packages enable attackers to gain remote access and steal information across Windows, Linux, and macOS systems immediately upon package import. This can lead to unauthorized data access, system compromise, and persistence on infected macOS devices. The use of multiple payload delivery methods and anti-analysis techniques increases the difficulty of detection and mitigation. The campaign's focus on Russian financial institutions suggests targeted espionage or financial crime motives. The Linux payload's use of a Sliver implant indicates advanced post-exploitation capabilities.
Mitigation Recommendations
No official patch or remediation is available as this is a supply chain malware campaign leveraging malicious packages in the NPM registry. Mitigation involves avoiding the use of suspicious or typo-squatted NPM packages, verifying package authenticity and publisher reputation before use, and monitoring for indicators of compromise such as connections to the listed domains (e.g., wel1.ru and its subdomains). Security teams should update detection rules to identify the hashes and domains associated with this campaign. Since this is not a vulnerability in software but a malware campaign, remediation focuses on supply chain security and package vetting.
Indicators of Compromise
- domain: wel1.ru
- domain: sdk.dl.wel1.ru
- domain: ext.dl.wel1.ru
- domain: pkg.dl.wel1.ru
- domain: net.dl.wel1.ru
- hash: d382fdae4e2675b94419fdb115dbd397
- hash: bc3ae1e11c283e9e3d57c02abf24870f4e8cfaa1
- hash: 0fc30f82e1fa5e51a6c0c43f3ed7f13592ea731cb331e43a4d085df60a4db8b6
- hash: 7e486657f30594afda379b97030252a09a19fe8055e25c9e371544f59bd8e9e3
- hash: 94ef6b1c4a9d31f78f446d053048bcef34fd88f4376a1a46f7f777a9e9c83a29
- hash: a3e2ffb440b779d30da3ff282affd649731088e8570df7b1aa72742d995b782c
- hash: b74c5675725911c62091bdf40714df760cc2af7a88360d21065f4e1c878aa8f0
- hash: c214746c74cae8ece8bdaf69aa05da4db6ce013f9e77452d1eed1a002fd9ba00
- hash: e2650e9aa2f924433ba422857b22ee7c5996b5ad306f3f903283f6a13e248935
- domain: 0.sdk.dl.wel1.ru
- domain: 1.sdk.dl.wel1.ru
- domain: 2.sdk.dl.wel1.ru
- domain: dl.wel1.ru
Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages
Description
A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign involves a threat actor publishing over 700 malicious NPM packages using AI-generated typo-squatting names to trick developers into importing them. The malicious packages deploy a cross-platform RAT and infostealer that execute immediately upon import via require(), bypassing the need for install scripts. Payload delivery rotates through three Cloudflare Workers hosts with a DNS TXT record fallback under the domain wel1.ru. The macOS payload achieves persistence through LaunchAgents and downloads additional beacons, while the Linux payload appears to deliver a Sliver implant. The campaign shares tradecraft with the Moika malware operation, including targeting Russian financial institutions, fake telemetry for camouflage, and similar kill switch mechanisms. The malware includes anti-analysis features that detect debuggers, virtualization environments, and packet capture tools to evade detection and analysis.
Potential Impact
The malicious NPM packages enable attackers to gain remote access and steal information across Windows, Linux, and macOS systems immediately upon package import. This can lead to unauthorized data access, system compromise, and persistence on infected macOS devices. The use of multiple payload delivery methods and anti-analysis techniques increases the difficulty of detection and mitigation. The campaign's focus on Russian financial institutions suggests targeted espionage or financial crime motives. The Linux payload's use of a Sliver implant indicates advanced post-exploitation capabilities.
Defensive Guidance
No official patch or remediation is available as this is a supply chain malware campaign leveraging malicious packages in the NPM registry. Mitigation involves avoiding the use of suspicious or typo-squatted NPM packages, verifying package authenticity and publisher reputation before use, and monitoring for indicators of compromise such as connections to the listed domains (e.g., wel1.ru and its subdomains). Security teams should update detection rules to identify the hashes and domains associated with this campaign. Since this is not a vulnerability in software but a malware campaign, remediation focuses on supply chain security and package vetting.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://opensourcemalware.com/blog/russian-ai-slopsquatting-npm-campaign"]
- Adversary
- null
- Pulse Id
- 6a76515e8fbfccabf4dbb65b
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainwel1.ru | — | |
domainsdk.dl.wel1.ru | — | |
domainext.dl.wel1.ru | — | |
domainpkg.dl.wel1.ru | — | |
domainnet.dl.wel1.ru | — | |
domain0.sdk.dl.wel1.ru | — | |
domain1.sdk.dl.wel1.ru | — | |
domain2.sdk.dl.wel1.ru | — | |
domaindl.wel1.ru | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashd382fdae4e2675b94419fdb115dbd397 | — | |
hashbc3ae1e11c283e9e3d57c02abf24870f4e8cfaa1 | — | |
hash0fc30f82e1fa5e51a6c0c43f3ed7f13592ea731cb331e43a4d085df60a4db8b6 | — | |
hash7e486657f30594afda379b97030252a09a19fe8055e25c9e371544f59bd8e9e3 | — | |
hash94ef6b1c4a9d31f78f446d053048bcef34fd88f4376a1a46f7f777a9e9c83a29 | — | |
hasha3e2ffb440b779d30da3ff282affd649731088e8570df7b1aa72742d995b782c | — | |
hashb74c5675725911c62091bdf40714df760cc2af7a88360d21065f4e1c878aa8f0 | — | |
hashc214746c74cae8ece8bdaf69aa05da4db6ce013f9e77452d1eed1a002fd9ba00 | — | |
hashe2650e9aa2f924433ba422857b22ee7c5996b5ad306f3f903283f6a13e248935 | — |
Threat ID: 6a7987aabf8831d539529461
Added to database: 08/10/2026, 08:11:22 UTC
Last enriched: 08/10/2026, 09:03:10 UTC
Last updated: 08/10/2026, 14:18:28 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.