Tech

NPM users warned dozens of malicious packages aim to steal host and network data

Share
Share


  • Socket found 60 malicious NPM packages
  • The malware spoofed legitimate packages
  • It was capable of exfiltrating sensitive data

Cybersecurity researchers Socket have warned of multiple malicious packages hosted on NPM, stealing sensitive user data and relaying it to the attackers.

In a blog post, Socket said it identified 60 packages on NPM, which were uploaded from May 12 onward, using three separate accounts. The packages contained a post-install script that runs during ‘npm install’ and exfiltrates hostnames, internal IP addresses, user home directories, current working directories, usernames, and system DNS servers.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Over a million critical severity records exposed in Q1 2025 alone – make sure you’re not at risk
Tech

Over a million critical severity records exposed in Q1 2025 alone – make sure you’re not at risk

Norton’s Gen Threat Report reveals worrying trends in cybersecurity Scams and data...

McAfee adds powerful scam detector to antivirus plans, but is it worth paying for when others offer it for free?
Tech

McAfee adds powerful scam detector to antivirus plans, but is it worth paying for when others offer it for free?

McAfee says Scam Detector hits 99% accuracy, including deepfake spotting on video...

An official Nothing Phone 3 teaser just arrived, though it may be dropping a signature feature
Tech

An official Nothing Phone 3 teaser just arrived, though it may be dropping a signature feature

Nothing has teased its Phone 3 flagship The traditional glyphs are apparently...