npm Mirrors Turned into Phishing Hosts
Attackers abuse npm mirrors to host HTML phishing pages, bypassing security filters by serving from legitimate domains.
17 results for “npm”
Attackers abuse npm mirrors to host HTML phishing pages, bypassing security filters by serving from legitimate domains.
Researchers uncover 14 malicious npm packages delivering RedC2 4.0, an AI-assisted Linux backdoor, via stealthy loader.
Sonatype finds six npm packages reading C2 addresses from an Ethereum wallet transaction linked to DPRK.
A self-propagating malware campaign has compromised over 1,300 npm packages, leveraging legitimate GitHub workflows to spread.
New npm malware hides command-and-control infrastructure within zero-value Ethereum transfer addresses to bypass traditional detection.
A critical shell injection vulnerability in the Shescape library allows attackers to bypass security filters when using CMD on Windows systems.
A type confusion vulnerability in seroval.fromJSON() allows attackers to trigger unintended server-side code execution through malicious JSON payloads.
A severe vulnerability in the node-tar library allows attackers to crash servers and exhaust storage through maliciously crafted archive files.
A new campaign targeting Vite developers uses a four-tier blockchain infrastructure to bypass traditional security takedown efforts.
Compromised AsyncAPI and Jscrambler packages expose developers to credential theft via automated malicious injection.
A sophisticated supply chain attack used legitimate GitHub pipelines to push malicious code via the AsyncAPI npm namespace.
Compromised publishing credentials allowed attackers to inject malicious binaries into widely used Jscrambler NPM versions.
A swarm of 148 malicious npm packages exploited student browsers to fuel a sophisticated, dual-layered botnet operation.
A malicious npm package injection forced a swift cleanup, highlighting the persistent dangers of compromised build environments.
A compromised jscrambler package release highlights how modern software pipelines are weaponized to harvest developer secrets.
A compromised developer account on GitHub allowed attackers to inject silent credential-stealing malware into a popular Web3 ecosystem.
GitHub's npm 12 release hardens software supply chains by disabling install scripts by default and overhauling granular access tokens to mitigate critical risks.