organization · 3 records
OpenSourceMalware

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Researchers discovered 13 malicious npm packages distributing a new stealer called WeaselBiscuit that targets Chrome extension storage.
1 outlet

Two malicious npm packages infect Node.js environments with remote access trojan
Two compromised npm packages in the @joyfill namespace deliver a remote access trojan associated with DEV#POPPER when imported into Node.js environments.
1 outlet

Researchers identify seven malicious npm packages targeting the Vite ecosystem
Researchers uncovered a supply chain attack involving seven malicious npm packages targeting the Vite ecosystem that use a multi-tier blockchain command-and-control infrastructure to deliver a remote access trojan.
1 outlet