National Cyber Warfare Foundation (NCWF)

Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer


0 user ratings
2026-06-29 06:16:03
milo
Attacks
Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts.

"This attack avoids the most common npm execution paths through lifecycle scripts, perhaps in an attempt to remain 'compatible' with npm v12's security hardenings," JFrog said in a



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/06/hijacked-npm-and-go-packages-use-vs.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Attacks



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.