The novel malware strain is being dubbed Shai-Hulud — after the name for the giant sandworms in Frank Herbert’s Dune novel ...
"Each published package becomes a new distribution vector: as soon as someone installs it, the worm executes, replicates, and ...
Hackers hijacked NPM libraries in a massive supply chain attack, injecting malware that swaps crypto wallet addresses to steal funds.
JavaScript packages with billions of downloads were compromised by an unknown threat actor looking to steal cryptocurrency.
An attack targeting the Node.js ecosystem was just identified — but not before it compromised 18 npm packages that account ...
A proof-of-concept multiplatform macro worm that can attack OpenOffice on Windows, Mac and Linux PCs, has been sent to security vendor Sophos. The "Badbunny" worm attempted to download and display an ...