NPM packages ethers-provider2 and ethers-providerz were found to contain sophisticated malware capable of inserting malicious code into local instances of a legitimate package, creating a reverse shell to easily infiltrate victims. While removed, the malware persists, highlighting growing issues with software supply chain risks. Researchers also found potential links to other malicious packages, pointing to the need for increased vigilance and robust security.

IXON VPN Vulnerabilities Let Attackers Gain Access to Windows & Linux Systems
A security assessment by Shelltrail revealed three critical vulnerabilities in the IXON VPN client, allowing privilege escalation on Windows and Linux. Identified as CVE-2025-ZZZ-01, CVE-2025-ZZZ-02,