
Malicious sjs-biginteger Implants SSH Backdoor
sjs-biginteger typosquats big.js on npm, implanting an SSH backdoor by injecting attacker keys into authorized_keys, opening firewall port 22, and exfiltrating credentials to C2 infrastructure...

sjs-biginteger typosquats big.js on npm, implanting an SSH backdoor by injecting attacker keys into authorized_keys, opening firewall port 22, and exfiltrating credentials to C2 infrastructure...

A coordinated campaign of thirty-six malicious npm packages published by four sock-puppet accounts (umarbek1233, kekylf12, tikeqemif26, and umar_bektembiev1) targets Strapi CMS deployments with eight...

Analysis of compromised litellm 1.82.8 on PyPI: a .pth file triggers credential theft, AWS/K8s secret exfiltration, and persistent C2 backdoor on install.

A throwaway GitHub account submitted 219+ malicious pull requests in a single day, each carrying a 352-line payload that steals CI secrets, injects workflows, bypasses label gates, and scans /proc...

Analysis of malicious telnyx 4.87.1 and 4.87.2 on PyPI — a package with over 1 million monthly downloads: injected code uses WAV audio steganography to deliver payloads that steal credentials and...

A malicious npm package impersonating the popular pino logger was detected by SafeDep. The package hides obfuscated code inside a legitimate library file to steal environment secrets and send them to...