Trojanized jQuery Packages Spread via 'Complex' Supply Chain Attack
ID: ba4163fe-4afe-5cb5-a47c-539fa3a80dcd
STIX ID: report--ba4163fe-4afe-5cb5-a47c-539fa3a80dcd
Feed Name: Dark Reading
Date Published: 2024-07-09
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
**Supply-chain campaign distributing Trojanized jQuery packages** — Researchers found ~68 malicious packages on npm, GitHub, and jsDelivr that include a trojanized jQuery file modifying the end (and affecting fadeTo) method to steal website form data and send it to attacker-controlled domains; the packages exhibit high variability, were often published under new usernames, and appear manually assembled, increasing stealth and potential impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
