product · 3 records
Node.js

Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution
A critical vulnerability in the Next.js ImageResponse feature allows attackers to achieve remote code execution via specially crafted SVG inputs.
1 outlet Cyber read

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool
Threat actors are using the legitimate Node.js runtime to execute malicious scripts and deploy backdoors in targeted cyber attacks.
1 outlet Markets read

Two malicious npm packages infect Node.js environments with remote access trojan
Two compromised npm packages in the @joyfill namespace deliver a remote access trojan associated with DEV#POPPER when imported into Node.js environments.
1 outlet