Malicious npm Package Leverages Unicode Steganography, Google Calendar as C2 Dropper

Researchers studying cybersecurity have found a malicious program called “os-info-checker-es6” that poses as an operating system information tool in order to surreptitiously install a next-stage payload on vulnerable devices.

In a report sent to The Hacker News, Veracode stated that this campaign uses a Google Calendar event short link as a dynamic dropper for its final payload and smart Unicode-based steganography to conceal its initial malicious code.

On March 19, 2025, a user by the name of kim9123 submitted os-info-checker-es6 for the first time in the npm registry. As of this writing, 2,001 downloads have been made. Another npm package named “skip-tot” that has “os-info-checker-es6” listed as a dependency was also uploaded by the same user. There have been 94 downloads of the bundle.

A later version, which was released on May 7, 2025, has been discovered to contain obfuscated code in the “preinstall.js” file to read Unicode read more about Malicious npm Package Leverages Unicode Steganography Google Calendar as C2 Dropper.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *