Around 290 fake GitHub repositories impersonate legitimate security and developer tools while distributing infostealers to compromise credentials and sensitive data from developers.
An in-memory RAT named GoodPersonRAT is being distributed through fake LetsVPN installer packages and requires immediate vigilance regarding the origin of VPN software.
A compromised Jscrambler npm package containing infostealer malware was distributed by attackers in the npm registry and downloaded nearly 1,500 times.
Google and Microsoft pulled the 1.6-million-times-installed header-editing extension ModHeader after researchers discovered a dormant browsing-history-collector component.
The malware in jscrambler 8.14.0 is activated by the preinstall hook without explicit import or CLI command — installation alone is sufficient for execution.
The malware in jscrambler 8.14.0 is activated by the preinstall hook without explicit import or CLI command—installation alone is sufficient for execution.
Malware in jscrambler 8.14.0 is activated via the preinstall hook without explicit import or CLI command—installation alone is sufficient for execution.