News

Shai-Hulud is the third major supply chain attack targeting the NPM ecosystem after the s1ngularity attack and the recent ...
A year after a glitch at cybersecurity company CrowdStrike triggered a global computer outage affecting millions of computers ...
"After detecting several malicious Node Package Manager (NPM) packages in the public NPM registry, a third-party open source repository, we swiftly removed them and proactively rotated our keys in ...
The novel malware strain is being dubbed Shai-Hulud — after the name for the giant sandworms in Frank Herbert’s Dune novel ...
The bundle.js script is designed to steal npm, GitHub, AWS and GCP tokens. But it also installs TruffleHog – an open source ...
A new piece of malware is spreading through the popular tinycolor NPM library and more than 300 other packages, some of which ...
In January 2010, a highly targeted, vendor-specific cyberattack was launched by those yet to be identified. The Stuxnet worm was highly sophisticated — perhaps the most sophisticated attack that is ...
Hulud" has compromised hundreds of packages in the npm repository with a self-replicating worm that steals secrets like API key, tokens, and cloud credentials and sends them to external servers that ...
"Each published package becomes a new distribution vector: as soon as someone installs it, the worm executes, replicates, and ...
Storm worm, the latest virus to hit e-mail users in huge numbers, appears in the form of e-mails that contain links to fraudulent Websites whose servers are infected with a generic downloader. Storm ...
(see story). It represented some scary malware firsts and is likely a harbinger of worms to come. IT professionals need to understand Witty and what it did. Witty was the first worm to target a ...
Antivirus companies have long cautioned users against opening unexpected e-mail attachments or attachments sent by strangers, but because of a new e-mail worm spreading this week, antivirus companies ...