npm

JavaScript packages hide ‘protestware’ against Russian users

Security researchers from Socket have stumbled upon a digital booby trap set for Russian-language users within JavaScript packages. The researchers…

7 days ago

Veracode unravels 12-layer npm attack to find RAT

Security researchers at Veracode, during their routine monitoring of the open-source world, stumbled upon two seemingly harmless software packages on…

2 weeks ago

Package lurking in npm for six years waits to destroy your work

Socket’s threat researchers have uncovered a package lurking in npm for six years that awaits a remote command to wipe…

4 weeks ago