Not pretty, not Windows-only: npm phishing attack laces popular packages with malware
ID: 1467e5b1-8a91-5fce-9064-0e963feafaf3
STIX ID: report--1467e5b1-8a91-5fce-9064-0e963feafaf3
Feed Name: The Register (Security)
A supply-chain attack compromised maintainer accounts and published malicious releases of widely used npm packages (notably the "is" package v3.3.1 and several prettier/eslint-related packages). The malware is an obfuscated JavaScript loader that runs on Node.js across macOS, Linux and Windows, captures environment variables and configuration files, exfiltrates data via WebSocket, provides an interactive remote shell, and persists by overwriting index.js; the incident likely originated from phishing using a typosquatted npm clone and affects packages with millions of weekly downloads, posing broad risk to developer machines and downstream applications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
