cognitive cybersecurity intelligence

News and Analysis

Search

Malicious npm Packages Attacking Linux Developers to Install SSH Backdoors

Malicious npm Packages Attacking Linux Developers to Install SSH Backdoors

A supply chain attack targeting Linux developers in Telegram’s bot ecosystem was discovered in early 2025. Malicious npm packages, masquerading as legitimate libraries, delivered SSH backdoors and exfiltrated sensitive data. Utilizing a “starjacking” technique, they mimicked a trusted project, complicating detection. The malware establishes persistent access by modifying SSH keys and sends compromised data to an external server.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts

How to Secure the Extended Enterprise

How to Secure the Extended Enterprise

Modern organizations depend on third-party vendors, which brings significant cybersecurity risks, as over 60% of breaches exploit vendor vulnerabilities. Chief Information Security Officers (CISOs) can