News
VS Code extensions deployed sandbox-evasive malware to steal system data, developer credentials, and crypto wallets.
All malicious npm packages carried identical payloads for snooping sensitive network information from developers’ systems.
The npm registry is once again in the spotlight, this time battling a malware campaign using malicious packages to map ...
Security firm Socket warns flags a campaign targeting NPM users with tens of malicious packages that can hijack system information.
Security experts at Socket’s Threat Research team, have discovered a campaign in the NPM ecosystem, which includes Malicious ...
Cybersecurity researchers Socket have warned of multiple malicious packages hosted on NPM, stealing sensitive user data and relaying it to the attackers. In a blog post, Socket said it identified ...
60 packages have been discovered in the NPM index that attempt to collect sensitive host and network data and send it to a Discord webhook controlled by the threat actor. According to Socket’s ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results