Seven Malicious npm Packages Use Blockchain C2 to Deliver a Remote Access Trojan
Researchers discovered seven malicious npm packages that employ blockchain-based command-and-control (C2) infrastructure to deliver a Remote Access Trojan (RAT). This novel technique enables attackers to evade traditional detection methods and poses a significant threat to the software supply chain. Developers and organizations using npm should review their dependencies and take immediate action to mitigate risk.
Sources (2)
security
2 sources