cognitive cybersecurity intelligence

News and Analysis

Search

Dangerous npm package ‘patches’ legitimate software with malware

Researchers at ReversingLabs have uncovered a malicious package, “ethers-provider2,” in the npm repository which modifies a legitimate package to create a difficult-to-remove backdoor. The package targets the widely used Ethereum blockchain library, “ethers”. It replaces a file within the local ethers package with a malicious version, resulting in a persisting security threat. The package was removed from the repository after ReversingLabs reported it to npm.

Source: www.scmagazine.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts