Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer

Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts.

“This attack avoids the most common npm execution paths through lifecycle scripts, perhaps in an attempt to remain ‘compatible’ with npm v12’s security hardenings,” JFrog said in a

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been

Demis Hassabis has a plan to harness AI safely

Demis Hassabis has a plan to harness AI safely Source: Hacker News

After Losses, Retail Investors Flock to 3x Leverage as 2x Product Are Restricted

After Losses, Retail Investors Flock to 3x Leverage as 2x Product Are Restricted Source: Hacker News