organization · 3 records
PolinRider

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code
A malicious npm package named indexed-btree hid its execution logic within runtime code to bypass new npm security restrictions.
1 outlet Markets read

Two malicious npm packages infect Node.js environments with remote access trojan
Two compromised npm packages in the @joyfill namespace deliver a remote access trojan associated with DEV#POPPER when imported into Node.js environments.
1 outlet

Researchers identify seven malicious npm packages targeting the Vite ecosystem
Researchers uncovered a supply chain attack involving seven malicious npm packages targeting the Vite ecosystem that use a multi-tier blockchain command-and-control infrastructure to deliver a remote access trojan.
1 outlet