Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

At least five separate malicious npm campaign clusters, discovered in June 2026, are actively delivering Windows and Linux RATs, a native C rootkit, and credential stealers targeting developer toolchains including Claude Code, GitHub CLI, and SSH keys. Three packages impersonating the widely used postcss-selector-parser (127M weekly downloads) remain available on npm as of publication, lowering the barrier for accidental installation. One cluster overlaps a confirmed North Korean operation (PolinRider) that has compromised approximately 2,000 GitHub repositories to distribute BeaverTail and InvisibleFerret malware.

Author

Tech Jacks Solutions