Researchers have discovered 60 malicious npm packages in the package registry designed to gather hostnames, IP addresses, DNS servers, and user directories to a Discord endpoint. The security firm Socket identified the accounts through which these packages were published. The information harvested from these packages is believed to assist threat actors in identifying high-value targets for future campaigns. Simultaneously, some other malicious npm packages disguised as helper libraries for various JavaScript frameworks are available for download despite having destructive payloads.

The True Cost of Focusing on Cost Instead of Cost-Effectiveness
When payors consider only the cost of the medication and not the cost and risk to the patient, doctor, and healthcare system, the irony is


