Tag

Npm Packages

All articles tagged with #npm packages

WaterPlum: North Korea-linked group hits 30,000 devices, transfers $10.7M in crypto
technology19 days ago

WaterPlum: North Korea-linked group hits 30,000 devices, transfers $10.7M in crypto

A joint law-enforcement advisory says the North Korean group WaterPlum compromised at least 30,000 devices in 100+ countries from Dec 2025 to July 2026, siphoning more than $10.7 million in cryptocurrency to DPRK. Linked to the Contagious Interview operation, WaterPlum used fake AI/crypto job interviews and malicious npm packages to infect targets, stealing wallet data, credentials, and other information, and sometimes pivoting into victims' networks. Malware families linked to WaterPlum include BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. Investigators note some actors also work as remote IT staff and reuse identities, including AI face-swapping during interviews. Authorities urge rigorous applicant verification and sandboxed code analysis to mitigate risk.

Malicious npm Packages Exploit Phishing to Steal Login Credentials
cybersecurity9 months ago

Malicious npm Packages Exploit Phishing to Steal Login Credentials

Cybersecurity researchers uncovered a targeted spear-phishing campaign using 27 malicious npm packages to host browser-based phishing lures mimicking document-sharing portals and Microsoft sign-in pages, primarily targeting organizations in critical infrastructure sectors across multiple countries. The campaign leverages package CDNs for resilient hosting, employs anti-analysis techniques, and hard-codes specific email addresses, with the goal of stealing login credentials. The activity highlights ongoing threats in the software supply chain, emphasizing the need for stringent dependency verification and monitoring.

Security Risks in VS Code Extensions: Ransomware, Cryptomining, and Supply Chain Threats
cybersecurity11 months ago

Security Risks in VS Code Extensions: Ransomware, Cryptomining, and Supply Chain Threats

Cybersecurity researchers discovered a vibe-coded malicious VS Code extension with built-in ransomware capabilities, which exfiltrates and encrypts files, and uses GitHub as a command-and-control server. Additionally, 17 npm packages disguised as SDKs were found to stealthily deploy Vidar Stealer, highlighting ongoing supply chain threats in open-source ecosystems. Microsoft has removed the malicious extension from the marketplace, emphasizing the importance of vigilance in software development.