Many People Installing Fake npm Packages Pretending to be Authentic Tools

Malicious individuals have been seen uploading deceptive alternatives of legitimate npm bundles like eslint-typescript and @types/node that have accumulated a large number of installations on the package repository.

Malicious individuals have been seen uploading deceptive alternatives of legitimate npm bundles like eslint-typescript and @types/node that have accumulated a large number of installations on the package repository.
The fraudulent iterations, titled @typescript_eslinter/eslint and types-node, have been designed to install a trojan and fetch secondary payloads, correspondingly.
“Although deceiving with typosquatting attacks,

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.