Malware found on npm infecting local package with reverse shellFor the first time, RL researchers discover malicious locally-installed npm packages infecting other legitimate packages.#reversinglabs#EN#2025#npm#packages#ethers-provider2#reverse-shell#malicious#locally-installed·reversinglabs.com·Mar 28, 2025Malware found on npm infecting local package with reverse shell
A new playground: Malicious campaigns proliferate from VSCode to npmTo avoid compromised packages being introduced as a dependency in a larger project, security teams need to keep an eye peeled for such malicious code.#reversinglabs#EN#2024#Malicious#VSCode#npm#Supply-Chain-Attack·reversinglabs.com·Dec 20, 2024A new playground: Malicious campaigns proliferate from VSCode to npm
Operation Brainleeches: Malicious npm packages fuel supply chain and phishing attacks“Write once, infect everywhere” might be the new cybercrime motto, with newly discovered campaigns showing malicious npm packages powering phishing kits and supply chain attacks.#reversinglabs#EN#NPM#Malicious#packages#supplychain#Supply-Chain-Attack·reversinglabs.com·Jul 7, 2023Operation Brainleeches: Malicious npm packages fuel supply chain and phishing attacks