More

    More popular npm packages hijacked to spread malware




    • A npm package maintainer has fallen victim to a phishing attack
    • The attackers accessed packages and updated them to carry malware
    • Most antivirus programs are still not properly flagging the malicious DLL

    Several popular npm packages with millions of weekly downloads were targeted, and one used as a launchpad for malware deployment, when its maintainer fell prey to a phishing attack.

    JounQin is a software developer that maintains eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core, and napi-postinstall.

    https://cdn.mos.cms.futurecdn.net/S2k99RTyJJhGbDwQRHUsyg.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    spot_imgspot_img