View Single Post
Staro 20.04.2025., 21:44   #37
tomek@vz
White Rabbit
 
tomek@vz's Avatar
 
Datum registracije: May 2006
Lokacija: -
Postovi: 5,010
Citiraj:
Cybersecurity researchers have uncovered three malicious packages in the npm registry that masquerade as a popular Telegram bot library but harbor SSH backdoors and data exfiltration capabilities.
The packages in question are listed below -
According to supply chain security firm Socket, the packages are designed to mimic node-telegram-bot-api, a popular Node.js Telegram Bot API with over 100,000 weekly downloads. The three libraries are still available for download.

> HackerNews
tomek@vz je online   Reply With Quote