generalnews.media
importance 4/5 Exclusive

Two tainted joyfill npm packages deploy RAT when used in Node.js

Two npm packages under the joyfill name have been compromised, executing a remote access trojan upon import into Node.js projects. This supply chain attack targets developers and could lead to full system compromise. Users are advised to verify package integrity and remove the malicious versions.

Security

Sources (1)

security
← Back to home