National Cyber Warfare Foundation (NCWF) Forums


Malicious NPM Packages Exfiltrate Hundreds of Developer SSH Keys via GitHub


0 user ratings
2024-01-23 14:30:27
milo
Developers

 - archive -- 
Two malicious packages discovered on the npm package registry have been found to leverage GitHub to store Base64-encrypted SSH keys stolen from developer systems on which they were installed.
The modules named warbeast2000 and kodiak2k were published at the start of the month, attracting 412 and 1,281 downloads before they were taken down by the npm



Source: TheHackerNews
Source Link: https://thehackernews.com/2024/01/malicious-npm-packages-exfiltrate-1600.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Developers



© Copyright 2012 through 2024 - National Cyber War Foundation - All rights reserved worldwide.