Get a Pentest and security assessment of your IT network.

News

Malicious npm package exfiltrating data from UNIX systems

A malicious JavaScript package was uploaded Dec. 30 2019 on the Node Package Manager (npm), the worlds largest software registry, containing over 800,000 code packages. The package, identified as 1337qq-js, was spotted stealing sensitive data through install scrips of Unix Systems. The data it collects includes running processes, environment variables, uname a, npmrc file and /etc/hosts. It marks the sixth-known incident to strike the npm repository in the past three years.”]

Source: https://www.bitdefender.com/blog/hotforsecurity/malicious-npm-package-exfiltrating-data-from-unix-systems/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin