Anonymous
7/24/2025, 12:22:31 PM No.106007909
>The popular npm package "is" was infected with cross-platform malware
>The malware captures data including all environment variables (often a source of secrets such as credentials), exfiltrates them via a WebSocket connection, and provides the attacker with an interactive remote shell. The malware runs on Node.js on macOS, Linux and Windows, and persists itself if possible by overwriting an index.js file so that even deleting the node_modules directory, which stores downloaded packages, will not remove it.
https://www.theregister.com/2025/07/24/not_pretty_not_windowsonly_npm/
>The malware captures data including all environment variables (often a source of secrets such as credentials), exfiltrates them via a WebSocket connection, and provides the attacker with an interactive remote shell. The malware runs on Node.js on macOS, Linux and Windows, and persists itself if possible by overwriting an index.js file so that even deleting the node_modules directory, which stores downloaded packages, will not remove it.
https://www.theregister.com/2025/07/24/not_pretty_not_windowsonly_npm/
Replies: