G2: Remote Script Loader in npm Proxy Campaign
A remote script loader module found in the malicious npm packages, which fetches JavaScript from a GitHub repository through the jsDelivr CDN…
A remote script loader module found in the malicious npm packages, which fetches JavaScript from a GitHub repository through the jsDelivr CDN…
pnpm is a package manager for JavaScript that emphasizes speed and disk space efficiency. It includes cooldown features to mitigate malicious package…
Windows Script Host was used to execute the initial JavaScript payload in the VEIL#DROP campaign, launching PowerShell with execution policy bypasses.
On June 17, 2026, a software supply chain attack codenamed 'easy-day-js' compromised 145 npm packages under the @mastra/* namespace, a popular open-source…
A known JavaScript malware associated with the Contagious Interview campaign. Delivered via malicious packages and extensions, it searches for configuration files and…
An analysis of a popular Google Chrome ad block extension for YouTube, named Adblock for YouTube (ID: cmedhionkhpnakcndndgjdbohmhepckk), has uncovered the ability…