Tag: NPM Package

Oracle customers confirm data stolen in alleged cloud breach is valid
News

Oracle customers confirm data stolen in alleged cloud breach is valid

Two malicious packages that are intended to infect another locally installed package have been found by cybersecurity experts on the npm registry, highlighting the ongoing development of software supply chain hacks that target the open-source community. Since its publication on March 15, 2025, the packages in question—ethers-provider2 and ethers-providerz—have been downloaded 73 times. No one downloaded the second package, which was probably deleted by the virus creator. In a study provided with The Hacker News, Lucija Valentić, a researcher from ReversingLabs, claimed that they were straightforward downloaders with a carefully concealed harmful payload. Their second stage, which would 'patch' the locally installed legitimate npm package ethers with a new file holding the malicio...
Malicious npm Package Modifies Local ‘ethers’ Library to Launch Reverse Shell Attacks
News

Malicious npm Package Modifies Local ‘ethers’ Library to Launch Reverse Shell Attacks

Two malicious packages that are intended to infect another locally installed package have been found by cybersecurity experts on the npm registry, highlighting the ongoing development of software supply chain hacks that target the open-source community. Since its publication on March 15, 2025, the packages in question—ethers-provider2 and ethers-providerz—have been downloaded 73 times. No one downloaded the second package, which was probably deleted by the virus creator. In a study provided with The Hacker News, Lucija Valentić, a researcher from ReversingLabs, claimed that they were straightforward downloaders with a carefully concealed harmful payload. Their second stage, which would 'patch' the locally installed legitimate npm package ethers with a new file holding the malicio...
Malicious Obfuscated NPM Package Disguised as an Ethereum Tool Deploys Quasar RAT
News

Malicious Obfuscated NPM Package Disguised as an Ethereum Tool Deploys Quasar RAT

Researchers studying cybersecurity have found a malicious package on the npm package registry that poses as a library for identifying Ethereum smart contract vulnerabilities but actually installs Quasar RAT, an open-source remote access trojan, on developer PCs. On December 18, 2024, the highly obfuscated package, ethereumvulncontracthandler, was posted to npm by a user going by the pseudonym "solidit-dev-416." It is still accessible for download as of this writing. So far, it has been downloaded sixty-six times. In an investigation released last month, Socket security researcher Kirill Boychenko said that when the RAT is installed, it obtains a malicious script from a distant server and discreetly runs it to install it on Windows systems read more about Malicious Obfuscated NPM Pac...