Get a Pentest and security assessment of your IT network.

Cyber Security

NPM Package Steals Chrome Passwords

Credential-stealing code bomb was found lurking in the Node.js open-source code repository. Researchers caught the malware filching credentials from Chrome on Windows systems via ChromePass. The password-stealer is multifunctional: It listens for incoming commands from the attacker s command-and-control (C2) server and can upload files and execute shell commands. Node.JS repository hosts more than 1.5 million unique packages, and serves up 1 billion requests for JavaScript packages per day to around 11 million developers worldwide.

Source: https://threatpost.com/npm-package-steals-chrome-passwords/168004/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security