All posts
Topic
Npm
2 articles on npm.
@apexacc/cli: Malicious npm Package Chains PowerShell, PyArmor and a Go Loader to Drop a Windows Infostealer
Elastic Security Labs is investigating @apexacc/cli, an npm package still live on the registry that disables Windows Smart App Control and AV exclusions, then chains Base64 PowerShell through Python/PyInstaller, PyArmor and a Go shellcode loader to an infostealer. What we know so far, credited to the source.
September 18, 2026
Shai-Hulud Took keyv โ and the Malware Shipped With Valid Provenance
A maintainer account compromise poisoned keyv, flat-cache, file-entry-cache and the rest of the family, then spread to 868 more packages across 1,381 versions โ over 2 billion monthly installs. The releases were signed by GitHub Actions and the provenance checks out. That is the part worth your attention.
August 4, 2026