Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer

Read full story on The Hacker News
Share
Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer
AI disclosure

Summary

Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts. "This attack avoids the most common npm execution paths through lifecycle scripts, perhaps in an attempt to remain 'compatible' with npm v12's security hardenings," JFrog said in a

Original reporting

Open original source
Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.