Socket discovered 10 malicious npm packages delivering infostealer malware across Windows, Linux, and macOS. What's sophisticated: 4 layers of obfuscation hide payloads, fake CAPTCHA appears legitimat…
Category: Threat Alerts / Supply Chain / Supply Chain
#npm#supply-chain#typosquatting#infostealer#malware#developer-targeting#credential-theft
Koi Security discovered PhantomRaven campaign compromising 86,000+ npm downloads via Remote Dynamic Dependencies (RDD)—an obscure npm feature allowing HTTP URLs as package dependencies. What's clever:…
Category: Threat Alerts / Supply Chain / Supply Chain
#npm#supply-chain#phantomraven#slopsquatting#ai-assisted-attacks#credential-theft#rdd