Get a Pentest and security assessment of your IT network.

News

Malicious Packages Disguised as JavaScript Libraries Found

Malicious packages disguise themselves as legitimate JavaScript libraries on npm registries to launch cryptominers on Windows, macOS and Linux machines. The malicious packages are dubbed okhsa – cataloged as Sonatype-2021-1473 – and klow and klown – catalogued as SonAtype-2020-1472. The researchers attributed the ownership of the malicious packages to an author whose account is currently deactivated, the report notes. The NotPetya and SolarWinds Orion attacks are not limited to commercial software updates.”]

Source: https://www.cuinfosecurity.com/malicious-packages-disguised-as-javascript-libraries-found-a-17782

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Who and why is attacking companies in the Nordic Countries?

News

Shamoon Malware, cyber espionage tool, cyber weapon or