BRIDGEHEAD: An npm typosquatting campaign that crosses from WSL into Windows to plant a crypto-wallet stealer

Reported 20 Aug 2026 by otx · Severity: medium

In August 2026, an operator published forty typosquatted npm packages mimicking popular libraries like chalk, axios, commander, lodash, react, and typescript. Each package contained an install script that profiles the host and, when detecting Windows or WSL environments, download