Tag: malicious npm packages
3 articles

Malicious npm Packages Target Alibaba Developers with Cross-Platform RAT
Researchers have uncovered a sneaky plot involving 18 malicious npm packages that deliver a cross-platform remote access trojan (RAT) to Alibaba developers, likely for industrial espionage. This targeted supply-chain operation zeroes in on Chinese-speaking environments, putting sensitive data at risk.

Malicious npm Packages Deliver Windows RAT via PostCSS Tooling
Beware of malicious npm packages masquerading as popular tools like PostCSS - researchers have uncovered three fake packages that have racked up over 1,000 downloads and deliver a sneaky Windows remote access trojan. These lookalike packages, published just over a month ago, have been cleverly designed to fly under the radar.

Shai Hulud Campaign Targets Developers with Malicious npm Packages
Malicious actors have unleashed a barrage of 84 tainted versions of popular software packages, cleverly disguising them with legitimate credentials to deceive developers. The Shai Hulud campaign, linked to the TeamPCP threat group, has been wreaking havoc on the software supply chain since September.