Black Lotus Labs researchers found that malware installation in targeted routers allows the deployment of a cd00r variant. This scans for five network signals, triggering reverse shell creation on the local file system, enabling device takeover, data theft, and further malware compromise.

NPM flooded with malicious packages downloaded more than 86,000 times
Attackers are exploiting a major weakness that has allowed them access to the NPM code repository with more than 100 credential-stealing packages since August, mostly


