source code red horizontal logo
  • HOME
  • SERVICES
    • SOFTWARE SUPPLY CHAIN RED TEAMING
    • PENETRATION TESTING
    • DEVSECOPS CONSULTANCY
  • TRAINING
    • HOW TO SECURE CI/CD
    • SOFTWARE SUPPLY CHAIN
    • IN PERSON TRAINING
    • REVIEWS
  • BLOG
  • CONTACT
source code red horizontal logo
  • HOME
  • SERVICES
    • SOFTWARE SUPPLY CHAIN RED TEAMING
    • PENETRATION TESTING
    • DEVSECOPS CONSULTANCY
  • TRAINING
    • HOW TO SECURE CI/CD
    • SOFTWARE SUPPLY CHAIN
    • IN PERSON TRAINING
    • REVIEWS
  • BLOG
  • CONTACT
  • Follow
  • Follow
  • Follow
  • Follow
Malicious NPM package infects developers with new infostealer malware

Malicious NPM package infects developers with new infostealer malware

by Paul McCarty | Jan 26, 2025 | Uncategorized

SourceCodeRED identified a malicious package deployed on NPM this week.   This package was deployed by an NPM user named Zyrudev and named “arcus-cmd-utils”.   The package only contained two files:  index.js and package.json.   When this package was...
Malicious NPM packages target marked-js library

Malicious NPM packages target marked-js library

by Paul McCarty | Jan 10, 2025 | Uncategorized

Two NPM packages masquerading as legitimate javascript libraries were published to the NPM registry this week.  The packages were published by a user named “kamations” and target the marked-js ecosystem.  Two of the packages appear to be carbon copies of...
Snyk security researcher deploys malicious NPM packages targeting Cursor.com

Snyk security researcher deploys malicious NPM packages targeting Cursor.com

by Paul McCarty | Jan 8, 2025 | Uncategorized

Published January 8, 2025 Every morning I get up and check what malicious packages my detector had found the night before.   It’s like someone checking their fishing nets to see what fish they caught. As I was looking at last nights malicious packages I noticed...

Recent Posts

  • NPM package targets web3 smart contracts with new malware
  • NPM package targeting crypto wallets uses new language to evade detection
  • 3 myths about npm based threats
  • Malicious web3-parser NPM package targets crypto & web3 projects
  • NPM package targeting Prettier ecosystem drops malware

Recent Comments

No comments to show.

Archives

  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • July 2024
  • June 2024
  • April 2024
  • July 2023
  • June 2023

Categories

  • Uncategorized
sourcecodered-logo
  • Follow
  • Follow
  • Follow
  • Follow

Copyright © 2024 – SOURCECODERED All Rights Reserved