threat-intel
Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware
High
Summary
Four npm packages have been identified as containing malicious code, including a clone of the Shai-Hulud worm. One package delivers a DDoS botnet (Phantom Bot), while the others function as infostealers, stealing sensitive data like SSH keys and credentials. This incident highlights a concerning trend of supply chain attacks leveraging open-source malware.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
