Researchers at ReversingLabs have uncovered a malicious package, “ethers-provider2,” in the npm repository which modifies a legitimate package to create a difficult-to-remove backdoor. The package targets the widely used Ethereum blockchain library, “ethers”. It replaces a file within the local ethers package with a malicious version, resulting in a persisting security threat. The package was removed from the repository after ReversingLabs reported it to npm.

Hackers Scanning From 24,000 IP’s to Gain Access to Palo Alto Networks
Researchers observed a significant increase in malicious scanning of Palo Alto Networks’ GlobalProtect VPN portals, with nearly 24,000 unique IP addresses targeting the systems. This