cognitive cybersecurity intelligence

News and Analysis

Search

New NPM Attack Infecting Local Packages With Cleverly Hidden Malicious Payload

NPM packages ethers-provider2 and ethers-providerz were found to contain sophisticated malware capable of inserting malicious code into local instances of a legitimate package, creating a reverse shell to easily infiltrate victims. While removed, the malware persists, highlighting growing issues with software supply chain risks. Researchers also found potential links to other malicious packages, pointing to the need for increased vigilance and robust security.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts