Popular NPM packages with over a million downloads hit by malware




  • 17 NPM packages with more than a million weekly downloads were compromised to deliver a RAT
  • The attack could turn into a major supply chain attack, experts warned
  • The packages were since deprecated, but users should be on their guard

More than a dozen packages on NPM were poisoned with a Remote Access Trojan (RAT), possibly infecting millions of projects.

Cybersecurity researchers Aikido Security recently discovered malicious code buried very deep in 17 popular Gluestack packages.

https://cdn.mos.cms.futurecdn.net/hsp2hXrMRpqTNDhd2ZFJof.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img