Popular NPM packages with more than one million downloads beaten by malware




  • 17 NPM packages with more than one million weekly downloads committed to deliver a rat
  • The attack could become a great attack on the supply chain, experts warned.
  • The packages were in disuse, but users should be on guard

More than a dozen NPM packages were poisoned with a remote access Trojan (rat), possibly infecting millions of projects.

Cybersecurity researchers Aikido Security recently discovered a very deep malicious code in 17 popular gluestack packages.

Leave a Comment

Your email address will not be published. Required fields are marked *