Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • Automate invoice and AP management
    • Hyundai’s robo-charger enhances EV convenience at major airport
    • Berlin-based VOYA Games raises €4.4 million to launch debut title Craft World – a dinosaur apocalypse crafting game
    • Best PC Gaming Monitors (2025): Samsung. AOC, and More
    • Intuit stock jumps 9%+ after reporting Q3 revenue up 15% YoY to $7.8B with FY 2025 guidance of $18.72B to $18.76B, up from $18.16B to $18.35B (Ashley Capoot/CNBC)
    • Costco Offering Buy Now, Pay Later With Affirm. But Is It Worth It?
    • AI system resorts to blackmail if told it will be removed
    • How to Evaluate LLMs and Algorithms — The Right Way
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Friday, May 23
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»Destructive malware available in NPM repo went unnoticed for 2 years
    News

    Destructive malware available in NPM repo went unnoticed for 2 years

    Editor Times FeaturedBy Editor Times FeaturedMay 23, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link

    A few of the payloads have been restricted to detonate solely on particular dates in 2023, however in some circumstances a part that was scheduled to start in July of that 12 months was given no termination date. Pandya mentioned meaning the menace stays persistent, though in an e-mail he additionally wrote: “Since all activation dates have handed (June 2023–August 2024), any developer following regular bundle utilization at this time would instantly set off harmful payloads together with system shutdowns, file deletion, and JavaScript prototype corruption.”

    Curiously, the NPM consumer who submitted the malicious packages, utilizing the registration e-mail tackle 1634389031@qq[.]com, additionally uploaded working packages with no malicious capabilities present in them. The method of submitting each dangerous and helpful packages helped create a “facade of legitimacy” that elevated the possibilities the malicious packages would go unnoticed, Pandya mentioned. Questions emailed to that tackle obtained no response.

    The malicious packages focused customers of a number of the largest ecosystems for JavaScript builders, together with React, Vue, and Vite. The particular packages have been:

    Anybody who put in any of those packages ought to fastidiously examine their methods to verify they’re now not operating. These packages completely mimic respectable improvement instruments, so it could be simple for them to have remained undetected.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    Intuit stock jumps 9%+ after reporting Q3 revenue up 15% YoY to $7.8B with FY 2025 guidance of $18.72B to $18.76B, up from $18.16B to $18.35B (Ashley Capoot/CNBC)

    May 23, 2025

    New Claude 4 AI model refactored code for 7 hours straight

    May 23, 2025

    VMware cloud partners demand “firm regulatory action” on Broadcom

    May 22, 2025

    Authorities carry out global takedown of infostealer used by cybercriminals

    May 22, 2025

    Apple legend Jony Ive takes control of OpenAI’s design future

    May 22, 2025

    “Microsoft has simply given us no other option,” Signal says as it blocks Windows Recall

    May 21, 2025
    Leave A Reply Cancel Reply

    Editors Picks

    Automate invoice and AP management

    May 23, 2025

    Hyundai’s robo-charger enhances EV convenience at major airport

    May 23, 2025

    Berlin-based VOYA Games raises €4.4 million to launch debut title Craft World – a dinosaur apocalypse crafting game

    May 23, 2025

    Best PC Gaming Monitors (2025): Samsung. AOC, and More

    May 23, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    The Twitch Streamer Using Face Recognition to Make Video Games More Accessible

    February 2, 2025

    Google Calendar Deletes Black History Month, Pride and Other Cultural Events

    February 19, 2025

    Elon Musk’s DOGE Seeks Access to Americans’ Data, Alarming Government Employees

    February 19, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.