Latest News

Breaking

Post Top Ad

Your Ad Spot

Thursday, November 28, 2024

XMLRPC npm Library Turns Malicious, Steals Data, Deploys Crypto Miner

Cybersecurity researchers have discovered a software supply chain attack that has remained active for over a year on the npm package registry by starting off as an innocuous library and later adding malicious code to steal sensitive data and mine cryptocurrency on infected systems. The package, named @0xengine/xmlrpc, was originally published on October 2, 2023 as a JavaScript-based XML-RPC

source https://thehackernews.com/2024/11/xmlrpc-npm-library-turns-malicious.html

No comments:

Post a Comment

please do not enter any spam link in the comment box

Post Top Ad

Your Ad Spot

Pages