#NPM

Vulnerability/Target

2023-06-23 • Phylum Discovers Sophisticated Ongoing Attack on NPM

npm is the Node Package Manager ecosystem used to publish and install JavaScript software packages. DPRK-linked operators have socially engineered maintainers, hijacked legitimate packages, and published malicious or typosquatted packages that execute loaders, steal credentials, establish remote access, and retrieve command-and-control information through public blockchains.

Tagged Reports

« Back