FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ The Hacker News

Npm Trojan Bypasses UAC, Installs AnyDesk with "Oscompatible" Package

By: Newsroom β€” January 19th 2024 at 07:42
A malicious package uploaded to the npm registry has been found deploying a sophisticated remote access trojan on compromised Windows machines. The package, named "oscompatible," was published on January 9, 2024, attracting a total of 380 downloads before it was taken down. oscompatible included a "few strange binaries," according to software supply chain security firm Phylum, including a single
☐ β˜† βœ‡ The Hacker News

Over 3 Dozen Data-Stealing Malicious npm Packages Found Targeting Developers

By: Newsroom β€” October 3rd 2023 at 14:59
Nearly three dozen counterfeit packages have been discovered in the npm package repository that are designed to exfiltrate sensitive data from developer systems, according to findings from Fortinet FortiGuard Labs. One set of packages – named @expue/webpack, @expue/core, @expue/vue3-renderer, @fixedwidthtable/fixedwidthtable, and @virtualsearchtable/virtualsearchtable – harbored an obfuscated
☐ β˜† βœ‡ The Hacker News

Malicious npm Packages Aim to Target Developers for Source Code Theft

By: THN β€” August 30th 2023 at 11:27
An unknown threat actor is leveraging malicious npm packages to target developers with an aim to steal source code and configuration files from victim machines, a sign of how threats lurk consistently in open-source repositories. "The threat actor behind this campaign has been linked to malicious activity dating back to 2021," software supply chain security firm CheckmarxΒ saidΒ in a report shared
☐ β˜† βœ‡ The Hacker News

Over a Dozen Malicious npm Packages Target Roblox Game Developers

By: THN β€” August 23rd 2023 at 06:33
More than a dozen malicious packages have been discovered on the npm package repository since the start of August 2023 with capabilities to deploy an open-source information stealer calledΒ Luna Token GrabberΒ on systems belonging to Roblox developers. The ongoing campaign, first detected on August 1 by ReversingLabs, employs modules that masquerade as the legitimate packageΒ noblox.js, an API
❌