npm

ixpresso-core

ixpresso-core is identified in the SafeDep analysis "ixpresso-core: Windows RAT Disguised as a WhatsApp Agent". ixpresso-core poses as an AI WhatsApp agent on npm but installs Veltrix, a Windows RAT that steals browser credentials, Discord tokens, and keystrokes via a hardcoded Discord webhook.

discovered 2026-04-16

Threat types

ratcredential_stealercrypto_drainerdata_exfiltrationpersistencec2_agent

Malicious versions

  • 1.0.0
  • 1.0.1
  • 1.0.2

Campaigns

Indicators

Techniques

Read the full analysis →