60 Malicious npm Packages Discovered with Discord-Controlled Endpoint
Threat actors have published over 60 malicious npm packages that harvest hostnames, IP addresses, and user directories to a Discord-controlled endpoint. The packages were discovered by security researchers Kirill Boychenko and Kush Pandya, who revealed the malicious functionality in a report last week. The affected packages were installed over 3,000 times and include basic sandbox-evasion … Read more