RSS
Naked Security
clickbait
NPM
rogue packages
scamming
NPM JavaScript packages abused to create scambait links in bulk
February 22, 2023
Honda
Podcast
Supply chain
S3 Ep65: Supply chain conniption, NetUSB hole, Honda flashback, FTC muscle [Podcast + Transcript]
January 13, 2022
SophosLabs Uncut
Threat Research
Danabot
Featured
node.js
XMRig
Node poisoning: hijacked package delivers coin miner and credential-stealing backdoor
October 24, 2021
CVE-2021-23406.
Javascript
node
Sandbox
vulnerablity
Poisoned proxy PACs! The NPM package with a network-wide security hole…
September 6, 2021
Backdoor
malicious package
Microsoft
Microsoft Vulnerability Research
Node Package Manager
UNIX
Malicious npm package taken down after Microsoft warning
January 15, 2020