Security researchers at ReversingLabs have identified a new malware attack on the npm package repository. The attack involves modifying two packages, ethers-provider2 and ethers-providerz, which work to ‘patch’ the popular Ethereum package, ethers, with a malicious file. This allows attackers to gain access to compromised systems. The attack is distinctive for the extensive lengths taken to hide the payload and cover its tracks.

Hackers Scanning From 24,000 IP’s to Gain Access to Palo Alto Networks
Researchers observed a significant increase in malicious scanning of Palo Alto Networks’ GlobalProtect VPN portals, with nearly 24,000 unique IP addresses targeting the systems. This