Minacce · 135 giorni fa
Un singolo publisher npm non si limita a rubare secret. Sta anche inoculando persistenza e foothold botnet, quindi il vero blast radius sono le workstation degli sviluppatori, gli host CI e le credenziali a cui possono accedere, non solo i quattro pacchetti stessi.
1 fonte che coprono questa storia
Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware
4 malicious npm packages with 3,006 downloads spread stealers and Phantom Bot, forcing removals and secret rotation.
Part of the PlainSec briefing for 2026-05-19