Executive Summary
In August 2026, a sophisticated campaign named BRIDGEHEAD was identified leveraging 40 typosquatted npm packages to target developers. These packages, imitating popular libraries like 'chalk' and 'axios', use install hooks to profile host environments. If the environment is Windows Subsystem for Linux (WSL), the malware executes a hidden PowerShell bridge to download and run a native Windows executable from GitHub, effectively crossing the boundary from the Linux shell to the Windows host.
The final payload is a 22MB Rust-based wrapper that decrypts an 11MB embedded payload directly into memory. Once active, the malware functions as a comprehensive stealer, targeting 26 cryptocurrency wallet paths, Chromium-based browser credentials (Edge, Brave), and Telegram Desktop sessions. It exfiltrates stolen data to the anonymous file-sharing service gofile.io, using public infrastructure to evade traditional domain-based takedowns and reputation-based filtering.
