Trojanized jQuery Packages Found on npm, GitHub, and jsDelivr Code Repositories
ID: 41b43863-55b5-5bd9-a2ea-78eef31a4d52
STIX ID: report--41b43863-55b5-5bd9-a2ea-78eef31a4d52
Feed Name: The Hacker News
Threat Score
Researchers identified a complex supply-chain campaign in which threat actors published approximately 68 trojanized jQuery packages to npm (and hosted the modified library via GitHub/jsDelivr) during May–June 2024. The malicious code, hidden in the rarely used 'end' function (invoked by 'fadeTo'), exfiltrates website form data to a remote URL; the packages appear manually assembled across many accounts and names to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
