Threats
Malicious npm Package "G_Wagon" Steals Browser Credentials and 100+ Cryptocurrency Wallets
A sophisticated malicious npm package disguised as a UI component library has been discovered deploying a multi-stage infostealer that targets browser credentials, over 100 cryptocurrency wallet extensions, cloud credentials, and messaging tokens, according to research published by Aikido Security. The package, named ansi-universal-ui, describes itself as "