Malicious code hidden in joyfill packages executes upon loading the CommonJS entry point—not via lifecycle hooks—and uses a multi-stage blockchain infrastructure for payload delivery that…
Malicious npm packages impersonate legitimate Rollup polyfills and enable North Korean actors to steal data and gain remote access to developer systems.
At least 32 Red Hat npm packages were infected with a credential stealer that simultaneously manipulated GitHub workflows to publish additional packages with forged SLSA…