BRIDGEHEAD: npm Typosquatting Campaign Targeting WSL and Windows
Score: 10/10

BRIDGEHEAD: npm Typosquatting Campaign Targeting WSL and Windows

The BRIDGEHEAD campaign utilizes 40 npm typosquatting packages to jump from WSL environments to Windows hosts, deploying a Rust-based stealer for cryptocurrency wallets and browser credentials.

Executive Summary

In August 2026, a sophisticated campaign named BRIDGEHEAD was identified leveraging 40 typosquatted npm packages to target developers. These packages, imitating popular libraries like 'chalk' and 'axios', use install hooks to profile host environments. If the environment is Windows Subsystem for Linux (WSL), the malware executes a hidden PowerShell bridge to download and run a native Windows executable from GitHub, effectively crossing the boundary from the Linux shell to the Windows host.

The final payload is a 22MB Rust-based wrapper that decrypts an 11MB embedded payload directly into memory. Once active, the malware functions as a comprehensive stealer, targeting 26 cryptocurrency wallet paths, Chromium-based browser credentials (Edge, Brave), and Telegram Desktop sessions. It exfiltrates stolen data to the anonymous file-sharing service gofile.io, using public infrastructure to evade traditional domain-based takedowns and reputation-based filtering.

Key Details

Threat Name

BRIDGEHEAD npm Campaign

Affects

—

Adversary

—

Malware/Tools

BRIDGEHEAD

Report Score

10out of 10
Quality Score
Excellent
IOC Quality9
TTP Details10
Detection Guidance9
Enterprise Relevance9
Clarity & Structure9
Technical Depth10

Sources