Topic: security detection
-
Malicious NPM Packages Downloaded 86,000+ Times
A security vulnerability in the NPM ecosystem allowed attackers to upload over 100 malicious packages, downloaded more than 86,000 times, exploiting Remote Dynamic Dependencies to fetch unverified code. The PhantomRaven campaign used these dependencies to bypass detection, as they remain invisibl...
Read More » -
19 Malicious Visual Studio Code Extensions Uncovered
A malicious campaign used 19 Visual Studio Code extensions to hide malware, often by embedding a tampered npm package or disguising a binary archive as a PNG image to evade detection. The attacks targeted developers by mimicking trusted tools, with some extensions executing a Trojan upon launch a...
Read More » -
Coupang Data Breach: 33.7 Million Users at Risk
A massive data breach at a major South Korean e-commerce firm compromised 33.7 million customer accounts, exposing personal details and potentially triggering fines nearing $900 million. The breach went undetected for nearly five months, with a former employee suspected of using retained access k...
Read More »