Take a fresh look at your lifestyle.

NPM users warned dozens of malignant packages aimed at stealing host and network data

- Advertisement -

0

- Advertisement -


  • Socket found 60 malignant NPM packages
  • The malware -expensive legitimate packages
  • It was able to exfil sensitive data

CyberSecurity Researchers Socket has warned of several malignant packages hosted on NPM, steal sensitive user data and pass on to the attackers.

In a blog post, Socket said that it identified 60 packages on NPM, which were uploaded from 12 May, using three separate accounts. The packages contain a post-install script that is performed during ‘NPM Instally’ and exfils host names, internal IP addresses, house folders, current workbooks, user names and System DNS servers.

- Advertisement -

- Advertisement -

- Advertisement -

Leave A Reply

Your email address will not be published.