No Result
View All Result
CloudReports
  • Home
  • Linux
  • Web development
  • Javascript
  • SQL
  • Ant Design tutorial
  • QR Code Scanner
  • Home
  • Linux
  • Web development
  • Javascript
  • SQL
  • Ant Design tutorial
  • QR Code Scanner
No Result
View All Result
CloudReports
No Result
View All Result
Home Javascript

NPM: three packets contained malicious code

npn by npn
December 16, 2020
in Javascript
Reading Time: 2 mins read
0
NPM: three packets contained malicious code
0
SHARES
193
VIEWS
Share on FacebookShare on Twitter

Contents

    • 0.1 READ ALSO
    • 0.2 Configuring VS Code for Node/JavaScript Development
    • 0.3 How does Nodejs solve the problem of high concurrency?
  • 1 The packages have been online for almost a year
  • 2 Several operations of the same type in the last three months
Rate this post

Three JavaScript packages were pulled from the npm portal on Thursday for distributing malicious code.

READ ALSO

Configuring VS Code for Node/JavaScript Development

Configuring VS Code for Node/JavaScript Development

August 2, 2021
1.3k
How does Nodejs solve the problem of high concurrency?

How does Nodejs solve the problem of high concurrency?

July 18, 2021
1.3k

According to the NPM security team, all three JavaScript libraries have opened shells on the computers of the developers who imported the packages into their projects. The term “shell” refers to code allowing potentially malicious actors to remotely connect to the infected computer and execute instructions.

The npm security team has stated that these shells can work on both Windows and * nix operating systems, such as Linux, FreeBSD, OpenBSD, and others.
 

The packages have been online for almost a year

These three packages were uploaded to the NPM portal almost a year ago, in mid-October 2019. Each module has been downloaded more than 100 times in total since its release. The names of the packages are:

  • plutov-slack-client
  • nodetest199
  • nodetest1010

“Any computer on which these packages are installed should be considered totally compromised. All secrets and keys stored on this computer should be immediately changed from another computer, ”warns the NPM security team. “The package must be removed, but since full control of the computer may have been compromised by an outside entity, removing the package is not guaranteed to remove all malware resulting from its installation,” they add. .

The security team regularly scans NPM’s JavaScript library collection, which is considered the largest package manager for any programming language.

Several operations of the same type in the last three months

While malicious packets are routinely removed, the removal of these three packages is the third major packet removal operation in the past three months.

In August, NPM removed a malicious JavaScript library designed to steal sensitive files from an infected user’s browser and the Discord app .

ADVERTISEMENT

In September, NPM removed four JavaScript libraries used for collecting user data and uploading stolen data to a public GitHub page.

Source: ZDNet.com

ShareTweetShare
Previous Post

25 years of JavaScript: the programming language that makes the world go round

Next Post

Npm module: a backdoor and ambush questions

npn

npn

Related Posts

Configuring VS Code for Node/JavaScript Development
Javascript

Configuring VS Code for Node/JavaScript Development

August 2, 2021
1.3k
How does Nodejs solve the problem of high concurrency?
Javascript

How does Nodejs solve the problem of high concurrency?

July 18, 2021
1.3k
Npm module: a backdoor and ambush questions
Javascript

Npm module: a backdoor and ambush questions

December 16, 2020
311
25 years of JavaScript: the programming language that makes the world go round
Javascript

25 years of JavaScript: the programming language that makes the world go round

December 16, 2020
597
The story of migrating 70,000 lines of JavaScript code to TypeScript
Javascript

The story of migrating 70,000 lines of JavaScript code to TypeScript

December 15, 2020
506
TypeScript 4.1 adopts literal template types
Javascript

TypeScript 4.1 adopts literal template types

December 15, 2020
227
Next Post
Npm module: a backdoor and ambush questions

Npm module: a backdoor and ambush questions

Discussion about this post

No Result
View All Result

Categories

  • Android (1)
  • Ant Design tutorial (7)
  • App/Game (2)
  • Javascript (16)
  • Layout and Routing (2)
  • Linux (9)
  • PC & LAPTOP (6)
  • PERSONAL FINANCES (1)
  • React (13)
  • SQL (2)
  • TECHNOLOGY & DIGITAL (7)
  • The Basics (5)
  • Web development (37)

Search

No Result
View All Result

Categories

  • Android (1)
  • Ant Design tutorial (7)
  • App/Game (2)
  • Javascript (16)
  • Layout and Routing (2)
  • Linux (9)
  • PC & LAPTOP (6)
  • PERSONAL FINANCES (1)
  • React (13)
  • SQL (2)
  • TECHNOLOGY & DIGITAL (7)
  • The Basics (5)
  • Web development (37)
No Result
View All Result
  • Home
  • Linux
  • Web development
  • Javascript
  • SQL
  • Ant Design tutorial
  • QR Code Scanner