Tech

Popular NPM packages with over a million downloads hit by malware

Share
Share


  • 17 NPM packages with more than a million weekly downloads were compromised to deliver a RAT
  • The attack could turn into a major supply chain attack, experts warned
  • The packages were since deprecated, but users should be on their guard

More than a dozen packages on NPM were poisoned with a Remote Access Trojan (RAT), possibly infecting millions of projects.

Cybersecurity researchers Aikido Security recently discovered malicious code buried very deep in 17 popular Gluestack packages.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Gemini’s new Scheduled Actions feature puts catching up with ChatGPT on its dayplanner
Tech

Gemini’s new Scheduled Actions feature puts catching up with ChatGPT on its dayplanner

Google Gemini’s app has a new Scheduled Actions feature to assign recurring...

15 things we learned at the Apple WWDC 2025 keynote
Tech

15 things we learned at the Apple WWDC 2025 keynote

Apple’s WWDC keynote is over for another year, but it left us...

Apple announces Vision Pro overhaul with visionOS 26 – here are the 6 biggest updates headed to Apple’s VR headset
Tech

Apple announces Vision Pro overhaul with visionOS 26 – here are the 6 biggest updates headed to Apple’s VR headset

At WWDC 2025 Apple has announced its next-generation of software including visionOS...