RSS
Naked Security
clickbait
NPM
rogue packages
scamming
NPM JavaScript packages abused to create scambait links in bulk
Honda
Podcast
Supply chain
S3 Ep65: Supply chain conniption, NetUSB hole, Honda flashback, FTC muscle [Podcast + Transcript]
SophosLabs Uncut
Threat Research
Danabot
Featured
node.js
XMRig
Node poisoning: hijacked package delivers coin miner and credential-stealing backdoor
CVE-2021-23406.
Javascript
node
Sandbox
vulnerablity
Poisoned proxy PACs! The NPM package with a network-wide security hole…
Backdoor
malicious package
Microsoft
Microsoft Vulnerability Research
Node Package Manager
UNIX
Malicious npm package taken down after Microsoft warning