Skip to main content

Tag: package hijacking

2 articles

Cluttered developer workspace with laptop, papers, and coffee cups.

Malware Exploits VS Code Tasks in Hijacked Packages

Researchers have uncovered a sneaky malware attack that hides in Visual Studio Code tasks, masquerading as a harmless "eslint-check" task that springs into action the moment you open a compromised package directory in VS Code. The malware cleverly disguises its executable payload as a font file, allowing it to slip past defenses undetected.

Analyst 207
Laptop screen displays ominous code in dimly lit workspace.

Red Hat npm Scope Hijacked to Spread Cloud Credential Malware

In a shocking 72 seconds, an attacker hijacked Red Hat's npm scope to spread malware, publishing 32 malicious packages that racked up nearly 10 million downloads. The sneaky move exploited the trust developers have in Red Hat's official namespace, turning it into a conduit for cloud credential malware.

Analyst 207