Popular npm linter packages hijacked via phishing to drop malware
ID: 8d29ebee-c47c-504c-bb2c-4f6d5e59cc91
STIX ID: report--8d29ebee-c47c-504c-bb2c-4f6d5e59cc91
Feed Name: Bleeping Computer
Popular npm packages (notably eslint-config-prettier and related libraries) were hijacked after a maintainer fell for a phishing email; attackers used stolen npm credentials to publish malicious package versions that include a postinstall script which runs a trojan DLL via rundll32 on Windows. The report lists specific affected package versions to avoid, notes low detection on VirusTotal for the bundled DLL, and recommends checking lockfiles, CI/build artifacts, and rotating secrets as mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
