More popular NPM packages diverted to spread malware


  • An NPM package manager was the victim of a phishing attack
  • The attackers accessed the packages and updated them to transport malware
  • Most antivirus programs still do not properly report the malicious DLL

Several popular NPM packages with millions of weekly downloads have been targeted, and that used as a launch for the deployment of malware, when its maintainer fell prey to a phishing attack.

Jounqin is a software developer who keeps ESLINT-Config-Prettier, ESLINT-PLUgin-Prettier, SYNCKIT, @ PKGR / CORE and NAPI-Postinstall.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top