Home United States USA — software Three npm packages found opening shells on Linux, Windows systems

Three npm packages found opening shells on Linux, Windows systems

281
0
SHARE

NPM staff: Any computer that has this package installed or running should be considered fully compromised.
Three JavaScript packages have been removed from the npm portal on Thursday for containing malicious code. According to advisories from the npm security team, the three JavaScript libraries opened shells on the computers of developers who imported the packages into their projects. The shells, a technical term used by cyber-security researchers, allowed threat actors to connect remotely to the infected computer and execute malicious operations. The npm security team said the shells could work on both Windows and *nix operating systems, such as Linux, FreeBSD, OpenBSD, and others.

Continue reading...