Attackers increasingly are using malicious JavaScript packages to steal data, engage in cryptojacking and unleash botnets, researchers say. More than 1,300 malicious packages have been identified in the most oft-downloaded JavaScript package repository used by developers, npm, in the last six months. Npm packages are being downloaded upwards of 20 billion times a week and installed across countless web-facing components of software and applications across the world. WhiteSource researchers identified some of the most common malware payloads that can steal credentials or crypto and run botnets.”]
Source: https://threatpost.com/malicious-npm-packages-web-apps/178137/