Nearly 800 malicious npm packages are using README instructions—not npm lifecycle scripts—to launch a cross-platform RAT and infostealer when developers import them with `require()`. The campaign targets Windows, macOS, and Linux, with payload delivery backed by Cloudflare Workers and DNS TXT records. Source
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!