Popular NPM packages with more than a million downloads struck by malware


  • 17 NPM packages with more than a million weekly downloads have been compromised to deliver a rat
  • The attack could be transformed into a major supply of supply chain, experts warned of experts
  • The packages have since been depreciated, but users should be on their care

More than a dozen packages on NPM were poisoned with a remote Trojan horse (rat), perhaps infecting millions of projects.

Aikido Security cybersecurity researchers recently discovered a malicious code buried very deep in 17 popular gluestack packages.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top