Four npm packages found opening shells and collecting info on Linux, Windows systems
Security Affairs
OCTOBER 17, 2020
“It is possible that all four packages were authored by the same attacker(s) despite conflicting data provided in the package.json manifests.” The malicious code could work on both Windows and *nix operating systems, including major distros, including Linux, FreeBSD, OpenBSD. ” reported Bleeping Computer.
Let's personalize your content