101 Malicious npm Packages Add Developers’ WhatsApp Accounts to Groups Without Consent

Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub.

“The malicious packages abuse the ‘Baileys’ WhatsApp open source project to add the victims to groups without their consent,” OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting A flaw in the Google Cloud Vertex AI SDK for Python let an attacker with no access

Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code

Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code Three high-severity security flaws have been disclosed in Hugging Face’s Diffusers library that could allow crafted model repositories to

I made a visual workspace for AI Automations

I made a visual workspace for AI Automations Source: Hacker News