FreshRSS

๐Ÿ”’
โŒ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
โ˜ โ˜† โœ‡ The Hacker News

Npm Trojan Bypasses UAC, Installs AnyDesk with "Oscompatible" Package

By: Newsroom โ€” January 19th 2024 at 07:42
A malicious package uploaded to the npm registry has been found deploying a sophisticated remote access trojan on compromised Windows machines. The package, named "oscompatible," was published on January 9, 2024, attracting a total of 380 downloads before it was taken down. oscompatible included a "few strange binaries," according to software supply chain security firm Phylum, including a single
โ˜ โ˜† โœ‡ The Hacker News

Over 3 Dozen Data-Stealing Malicious npm Packages Found Targeting Developers

By: Newsroom โ€” October 3rd 2023 at 14:59
Nearly three dozen counterfeit packages have been discovered in the npm package repository that are designed to exfiltrate sensitive data from developer systems, according to findings from Fortinet FortiGuard Labs. One set of packages โ€“ named @expue/webpack, @expue/core, @expue/vue3-renderer, @fixedwidthtable/fixedwidthtable, and @virtualsearchtable/virtualsearchtable โ€“ harbored an obfuscated
โŒ