BRIDGEHEAD : An npm typosquatting campaign that crosses from WSL into Windows to plant a crypto-wallet stealer
BRIDGEHEAD : An npm typosquatting campaign that crosses from WSL into Windows to plant a crypto-wallet stealer. The malware targets cryptocurrency wallets, browser credentials, cookies and Telegram sessions, while executing largely in memory and using...
What happened
BRIDGEHEAD : An npm typosquatting campaign that crosses from WSL into Windows to plant a crypto-wallet stealer. CloudSEK’s BRIDGEHEAD investigation exposes a 40-package npm typosquatting campaign that abuses WSL to reach Windows hosts and deploy a concealed Rust-based stealer. The security significance comes from trust: Windows or the affected component sits in a software, development or delivery path that downstream teams may already allow to run automatically.
That means the initial attacker does not necessarily need to target every downstream organization separately; compromising a trusted upstream component can carry the risk into many environments through normal updates, packages or automation. For the teams receiving that component, the first visible event may look like an ordinary build, scan, package update or deployment rather than a classic phishing attempt. The malware targets cryptocurrency wallets, browser credentials, cookies and Telegram sessions, while executing largely in memory and using public infrastructure for reconnaissance and exfiltration, making detection and takedown significantly harder.
Editorial note: this News Brief follows the available evidence and adds length only when additional facts or useful context are available. Where public reporting does not establish a specific victim sequence, CyberDeltaForce does not present one as fact.
What the reporting and advisory establish
CloudSEK’s BRIDGEHEAD investigation exposes a 40-package npm typosquatting campaign that abuses WSL to reach Windows hosts and deploy a concealed Rust-based stealer.
BRIDGEHEAD : An npm typosquatting campaign that crosses from WSL into Windows to plant a crypto-wallet stealer
What this means for your environment
Move from the published facts to the technical path, exposure conditions and defensive decisions that matter in a real environment.
Attack & Exploitation Path
The sequence below reconstructs the intrusion from the stages supported by public reporting. Undisclosed transitions remain explicitly marked rather than inferred.
a software, supplier, dependency or update relationship is part of the access path.
malware, a backdoor, loader, web shell or another persistent access mechanism is involved.
exfiltration or stolen information is part of the impact.
Why this matters to you
This is relevant beyond the organizations named in the headline because a compromised software supply chain can transfer risk to every downstream team that trusted the affected component. The key question is whether Windows entered your build, scanning or deployment path and what privileges it could reach there.
Does this deserve attention in my environment?
Check the conditions below against your use of Windows.
Select the conditions that are true in your environment. Leaving a condition unselected does not mean you are safe — it only means you have not marked it as applicable.
- Identify where Windows appears in developer workstations, CI/CD pipelines, containers and automation.
- Verify package, image and release provenance against trusted vendor or project guidance; do not rely only on a package name or latest tag.
- Review CI/CD, registry, source-control and cloud logs for unusual access or secret use associated with affected build paths.
- Rotate exposed build or deployment credentials if your investigation finds a compromised artifact or unauthorized use.
What remains unconfirmed
- Who was responsible has not yet been confirmed publicly.
- The final number of affected people or records may change as the investigation continues.
Sources & References
Original reporting and technical references are kept here for readers who want to verify the facts. Publisher names stay out of the reading flow above.