Malware Mayhem: New npm Package Turns Developers’ Desktops into RAT Nests
Cybersecurity researchers have detected a new npm package, glup-debugger-log, designed to drop a remote access trojan (RAT) on systems. Masquerading as a “logger for gulp,” this package has been downloaded 175 times and targets active developer machines. It highlights the growing sophistication of malware in open source ecosystems.

Hot Take:
Well, it seems like the npm registry is now the Wild West of the developer world. Who knew that “glup-debugger-log” was actually “glup-drop-a-RAT-on-your-system”? Maybe it’s time to start treating every new package like a suspiciously cheap taco stand—delicious, but probably bad for your health.
Key Points:
- New malicious npm package named “glup-debugger-log” discovered.
- The package masquerades as a logging tool for the gulp toolkit.
- It has been downloaded 175 times, targeting active developer machines.
- Uses two obfuscated JavaScript files to deploy and maintain a Remote Access Trojan (RAT).
- Phylum highlights the evolving sophistication of open-source malware.
Already a member? Log in here