More popular NPM packages that were hijacked to spread malware


  • An NPM -Packing Maintains has fallen victim to a phishing -attack
  • The attackers gained access to packages and updated them to wear malware
  • Most antivirus programs still do not correctly mark the malicious dll

Several popular NPM packages with millions of weekly downloads were targeted and one used as a starting plate for malware implementation as its maintenance fell prey for a phishing attack.

Jounqin is a software developer who maintains Eslint-Config-Preetier, Eslint-Plugin-Preetier, Synckit, @PKGR/CORE and NAPI PostInto.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top