RSS
Threat Research
advisory
NPM
Axios
Axios npm package compromised to deploy malware
Naked Security
clickbait
rogue packages
scamming
NPM JavaScript packages abused to create scambait links in bulk
Honda
Podcast
Supply chain
S3 Ep65: Supply chain conniption, NetUSB hole, Honda flashback, FTC muscle [Podcast + Transcript]
SophosLabs Uncut
Danabot
Featured
node.js
XMRig
Node poisoning: hijacked package delivers coin miner and credential-stealing backdoor
CVE-2021-23406.
Javascript
node
Sandbox
vulnerablity
Poisoned proxy PACs! The NPM package with a network-wide security hole…
Backdoor
malicious package
Microsoft
Microsoft Vulnerability Research
Node Package Manager
UNIX
Malicious npm package taken down after Microsoft warning