Skip to main content

Tag: malicious npm packages

4 articles

Laptop screen displays code in a coding environment amidst office workspace elements.

Malicious npm Packages Evade Detection by Hiding in Runtime Code

A sneaky malicious npm package, indexed-btree, has been hiding in plain sight by disguising its loader inside ordinary library code, allowing it to evade detection and rack up millions of downloads. This cleverly crafted package mimicked a legitimate B-tree utility, but with a sinister twist that went undetected until it was removed from the npm registry.

Analyst 207
Cluttered software development workspace with laptop, tools, and Chinese characters on a desk overlooking a blurred…

Malicious npm Packages Target Alibaba Developers with Cross-Platform RAT

Researchers have uncovered a sneaky plot involving 18 malicious npm packages that deliver a cross-platform remote access trojan (RAT) to Alibaba developers, likely for industrial espionage. This targeted supply-chain operation zeroes in on Chinese-speaking environments, putting sensitive data at risk.

Analyst 207
Software development workstation with laptop, coding tools, and notes in a brightly-lit neutral environment.

Malicious npm Packages Deliver Windows RAT via PostCSS Tooling

Beware of malicious npm packages masquerading as popular tools like PostCSS - researchers have uncovered three fake packages that have racked up over 1,000 downloads and deliver a sneaky Windows remote access trojan. These lookalike packages, published just over a month ago, have been cleverly designed to fly under the radar.

Analyst 207
Dimly lit development workspace with laptop and empty GitHub repositories or terminal windows.

Shai Hulud Campaign Targets Developers with Malicious npm Packages

Malicious actors have unleashed a barrage of 84 tainted versions of popular software packages, cleverly disguising them with legitimate credentials to deceive developers. The Shai Hulud campaign, linked to the TeamPCP threat group, has been wreaking havoc on the software supply chain since September.

Analyst 207