Node.js Backdoor Used in DPRK Malvertising Campaign
A Node.js backdoor deployed via fake macOS updates, using LaunchAgent for persistence and Ethereum smart contracts for C2 communication. It polls the…
A Node.js backdoor deployed via fake macOS updates, using LaunchAgent for persistence and Ethereum smart contracts for C2 communication. It polls the…
clientCode is a heavily obfuscated Node.js remote access trojan (RAT) that uploads files, retrieves JavaScript, collects host details, and reads clipboard data,…
n8n has patched a high-severity expression-sandbox escape vulnerability that allows authenticated workflow editors to execute operating-system commands on the server running the…
More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN,…
PhantomEnigma is a modular backdoor built on Inno Setup and Node.js, hidden inside patched Electron applications like Boostnote. It collects system information,…
Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security,…
A Node.js implementation of the Wisp protocol server by Mercury Workshop. It was exploited in the campaign due to its lack of…
This week's cybersecurity landscape is marked by a series of critical threats and vulnerabilities. Progress has urged ShareFile customers to shut down…
An unknown threat actor is exploiting CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp (CVSS 10.0), to deliver two new malware families:…
A heavily obfuscated Node.js loader delivered as jquery.js, executed via node.exe. It establishes encrypted communications with a remote server and retrieves additional…