cognitive cybersecurity intelligence

News and Analysis

Search

Sophisticated NPM Attack Leverages Google Calendar2 for Advanced Communication

Sophisticated NPM Attack Leverages Google Calendar2 for Advanced Communication

A malware campaign has been discovered within the npm package os-info-checker-es6. Initially appearing benign after being published in March 2025, it quickly evolved, using complex Unicode steganography and evasion techniques to avoid detection. It gained further sophistication in May, using Google Calendar as an intermediary dropper and executed payloads. The malware has been downloaded 655 times weekly, indicating its potential reach within the ecosystem.

Source: gbhackers.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts