Get a Pentest and security assessment of your IT network.

News

npm Blog Archive: `crossenv` malware on the npm registry

A package with a name very similar to the popular cross-env package was sending environment variables from its installation context out to the npm registry. The package naming was both deliberate and maliciousthe intent was to collect useful data from tricked users. All of hacktask s packages have been removed from the. npm registry, including the hacktask. address is banned from using. npm. It is not sufficient to prevent the human being behind it from trying again, but we felt it was a necessary gesture.”]

Source: https://blog.npmjs.org/post/163723642530/crossenv-malware-on-the-npm-registry

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

BlackEnergy exploits recently fixed flaws in Siemens WinCC

News

Google Chrome will block code injection from third-party software within 14 months