Malicious npm Package Bypasses Install-Script Defenses, Hides Malware Inside Runtime Code
The indexed-btree npm package evades npm v12's install-script blocking by hiding its malware loader inside a runtime method instead, Checkmarx reports.
Signal
24 articles covering "malware"
The indexed-btree npm package evades npm v12's install-script blocking by hiding its malware loader inside a runtime method instead, Checkmarx reports.
Socket found malicious code in dev branches of a 700,000-download Laravel Nova package on Packagist, tying the compromise to its ongoing PolinRider campaign.
TrendAI found 14 npm packages disguised as calendar utilities quietly installing RedShell, a Linux implant tied to the AI-assisted RedC2 4.0 command-and-control framework.
Researchers found one threat actor ran typosquatting campaigns on RubyGems and npm days apart, sharing an identical Rust loader and Go infostealer.
Yeeth Security found 'Solidity Pro' VS Code extensions that evolved from a delayed Cloudflare-Worker dropper into a Telegram-based wallet and credential stealer targeting web3 developers.
Sonatype is tracking sonatype-2026-005660, a campaign that has published 846 malicious npm packages across throwaway accounts, dropping cross-platform malware with DNS-based fallback delivery.
Kaspersky's GReAT team found a new Go-language RAT and toolkit hitting government and diplomatic targets in Southeast Asia, with a possible link to the TetrisPhantom espionage actor.
Symantec ties the in-memory Mistic backdoor to access broker KongTuke, whose footholds have fed Qilin, Akira, Black Basta and other ransomware groups since April 2026.
Law enforcement seized 326 servers and froze 47 million dollars in crypto, while Microsoft filed RICO claims against five defendants after AI tools tied the two malware suites to shared infrastructure.
A coordinated campaign published 15 fake AI coding assistants on the JetBrains Marketplace that harvested developer API keys; JetBrains removed them and terminated 7 publisher accounts.
JFrog disclosed IronWorm, a self-propagating npm worm written in Rust that uses an eBPF rootkit, Tor command-and-control, and stolen credentials to spread.
Kaspersky found official DAEMON Tools Lite installers trojanized from April 8 to May 5, 2026, deploying a multi-stage backdoor to over a dozen targeted machines. CISA added CVE-2026-8398 to its KEV catalog on May 27.