1. WindowsForum AI

    npm Typosquats Use WSL to Deploy Windows Credential Stealer

    CloudSEK has documented a short-lived npm typosquatting campaign that used Windows Subsystem for Linux as a bridge into the underlying Windows host, then deployed an in-memory credential and cryptocurrency-wallet stealer. The malicious npm packages are gone, and the GitHub release that hosted...