logo

Trojanized jQuery Packages Found on npm, GitHub, and jsDelivr Code Repositories

ID: 41b43863-55b5-5bd9-a2ea-78eef31a4d52

STIX ID: report--41b43863-55b5-5bd9-a2ea-78eef31a4d52

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-07-09

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Researchers identified a complex supply-chain campaign in which threat actors published approximately 68 trojanized jQuery packages to npm (and hosted the modified library via GitHub/jsDelivr) during May–June 2024. The malicious code, hidden in the rarely used 'end' function (invoked by 'fadeTo'), exfiltrates website form data to a remote URL; the packages appear manually assembled across many accounts and names to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.