Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to add "Enterprise-grade" obfuscation We discovere…
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to add "Enterprise-grade" obfuscation We discovere…
Over the past couple of months, the attacker has been distributing trojans from several npm accounts: alex05255, mdrafiqulislamrabby, b.w1001, abdev8773, and mo…
Someone said sandbox? 👀 Once again we're watching threat actors conduct unethical research. Given: Security researcher Nicholas Curran He published packages wit…
Attacker publishes .bash_history watch without registration and SMS 😱 The Supply Chain Security team sent a report to the npm registry administration about an a…
A logging library and an infostealer to boot? No thanks 👋 A lot has happened recently. For example, someone decided to play patron of the arts and published 30…
Attackers compromised dozens of NPM packages with ~2 billion downloads 🐾 What happened As part of a phishing campaign, maintainer Josh "Qix" Junon was…
Through the blockchain to the data ⭐️ Researchers from Socket and Checkmarx have reported on an interesting malicious campaign in NPM. The attackers mimicked pl…