October 4, 2026

Malicious npm Packages That Evade Defenses

This is an impressive piece of malware. Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.

Malicious npm Packages That Evade Defenses

This is an impressive piece of malware. Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.

This is an impressive piece of malware. Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.

Clive Robinson •


September 24, 2026 11:33 AM

@ Bruce, ALL,

From the article,

“Developers are advised not to rely on install-time scanning alone, and to also employ runtime behavioral analysis.”

I pointed out some years ago as part of “Castles-v-Prisons”[1] that malware could not hide it’s runtime signature or the changes it made to the legitimate softwares signiture especially when you had a hypervisor looking for such changes using “probabilistic” methods.

Today they call part of it “runtime behavioural analysis” but they miss a lot of security the use of “prisons” and “probabilistic security” gives over the “castle” environment.

I described various bits of “Castles-v-Prisons” here back more than a decade ago…

As @Thoth found a certain graduate of the UK Cambridge Computer labs who moved to “University College London” stole the work and set up a company to try and sell it…

So there might be something behind the idea 😉

And for those who read the conversations and remember them, it just shows how,

“You can read about it here first on this blog”.

[1] @Wael did not like using the full name so he shortened it via “C-v-P” to “CvP”.

Clive Robinson •


September 24, 2026 11:57 AM

@ Bad .js,

With regards,

“javascript is being incorporated almost everywhere, and it angers me that it’s even being shoved down everyone’s throat even where it’s not needed at all. Many, very many sites, apps, systems, operating systems, files – could do/function just fine without the pest called .js which is worse than what we had with the nasty flashplayer a while ago.”

Yup I pointed out that both JavaScript were bad news security wise many years ago on the pages of this blog.

And you would not believe the amount of grief I got because of it… (and never an apology from any of them).

Especially when I said people should turn JavaScript off in the browser and uninstall it and flash from their computers…

Well Flash went first as people quickly realised what bad news it actually was. Javascript is unfortunately still with us even though it’s worse security wise. The only saving grace is lots of people have made the defences against javaScript more significant than they used to be.

But the truth is I’ve yet to find a server that runs javascript on a clients computer that is actually worth bothering with…

The really annoying thing though is the clowns and crooks in the W3C… that insist that they must be able to run code on a client computer thus keep shoving such nonsense into Web Client specifications.

Every time they have forced some client side executable into Web Standards it has become a major security fault…

You would have thought they would have learnt by now… But apparently not…

Celos •


September 24, 2026 4:57 PM

Does not sound that impressive to me. More like what I would expect from a competent expert. I am pretty sure I have had the occasional student that could do this, no nation state needed.

lurker •


September 24, 2026 7:31 PM

@Bad .js
“It’s truly disgusting what money buys.”

It buys men’s souls. Always has.

freedom •


September 26, 2026 12:53 PM

Clive wrote :

Yup I pointed out that – JavaScript was bad news securitywise many years ago on the pages of this blog. And you would not believe the amount of grief I got because of it

Oh yes the criminals from the corporate-NSA mafia get really unhinged when their beloved JS is exposed as the cancer it is.

On the other hand, if you want to easily find out who the “feds” are, just look at who is in favor of JS.