comparemela.com

ReversingLabs researchers have identified a new, malicious supply chain attack affecting the npm platform. The “typosquatting” campaign first appeared in August and pushed a malicious package, node-hide-console-windows, which downloaded a Discord bot that facilitated the planting of an open source rootkit, r77. This is the first time ReversingLabs researchers have discovered a malicious open source package delivering rootkit functionality, and suggests that open source projects may increasingly be seen as an avenue by which to distribute malware. 

Related Keywords

Lucija Valenti ,Microsoft ,Reversinglabs Software Supply Chain Security ,Security Bloggers Network ,Rl Software Supply Chain Security ,Software Supply Chain Security ,Discord Remote Administration Tool ,Supply Chain Security ,Remote Administration ,Luna Grabber ,Windows Defender ,Visual Studio Code ,Reversinglabs Blog ,

© 2025 Vimarsana

comparemela.com © 2020. All Rights Reserved.