E4del RAT: Node.js-Based Malware Abusing FTP Banners
E4del is a Node.js-based remote access trojan delivered via FTP banner dead drop resolvers. It is embedded in a digitally signed Electron…
E4del is a Node.js-based remote access trojan delivered via FTP banner dead drop resolvers. It is embedded in a digitally signed Electron…
Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source Node.js sandbox library with over 2,900 stars on GitHub.…
isolated-vm, a popular open-source Node.js library for running untrusted JavaScript in V8 isolates, patched a critical vulnerability (GHSA-864f-rcv7-6rh4) in versions 6.2.0 and…
A Node.js backdoor deployed via fake macOS updates, using LaunchAgent for persistence and Ethereum smart contracts for C2 communication. It polls the…
clientCode is a heavily obfuscated Node.js remote access trojan (RAT) that uploads files, retrieves JavaScript, collects host details, and reads clipboard data,…
n8n has patched a high-severity expression-sandbox escape vulnerability that allows authenticated workflow editors to execute operating-system commands on the server running the…
More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN,…
PhantomEnigma is a modular backdoor built on Inno Setup and Node.js, hidden inside patched Electron applications like Boostnote. It collects system information,…
Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security,…
A Node.js implementation of the Wisp protocol server by Mercury Workshop. It was exploited in the campaign due to its lack of…