cognitive cybersecurity intelligence

News and Analysis

Search

Over 70 Malicious npm and VS Code Packages Found Stealing Data and Crypto

Over 70 Malicious npm and VS Code Packages Found Stealing Data and Crypto

Researchers have discovered 60 malicious npm packages in the package registry designed to gather hostnames, IP addresses, DNS servers, and user directories to a Discord endpoint. The security firm Socket identified the accounts through which these packages were published. The information harvested from these packages is believed to assist threat actors in identifying high-value targets for future campaigns. Simultaneously, some other malicious npm packages disguised as helper libraries for various JavaScript frameworks are available for download despite having destructive payloads.

Source: thehackernews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts