Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A new campaign has been discovered publishing nearly 800 malicious packages to the npm registry, designed to deliver a cross-platform remote access…
A new campaign has been discovered publishing nearly 800 malicious packages to the npm registry, designed to deliver a cross-platform remote access…
typo-crypto is a malicious npm package designed to impersonate crypto-js, first published in March 2025. It contained a trojanized file (core.js) and…
crypto-js is a legitimate npm package for cryptographic functions. typo-crypto was designed to impersonate crypto-js through typosquatting.
Zoom is a popular videoconferencing platform used for remote meetings and collaboration. It was impersonated by BlueNoroff in phishing campaigns using typosquatted…
Cybersecurity researchers at JFrog have uncovered a sophisticated NuGet typosquatting campaign targeting the popular Newtonsoft.Json library. The malicious package, named "Newtonsoftt.Json.Net," is…
Newtonsoft.Json is a widely used JSON framework for .NET that was impersonated in a typosquatting attack. The malicious fork 'Newtonsoftt.Json.Net' masqueraded as…
Cybersecurity researchers at Checkmarx have uncovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of…