Three Malicious NPM Packages Attacking Developers to Steal Login Credentials

Three malicious npm packages are targeting JavaScript developers to steal browser logins, API keys, and cryptocurrency wallet data. The packages, named bitcoin-main-lib, bitcoin-lib-js, and bip40, were uploaded to the public npm registry and posed as tools linked to the popular bitcoinjs project. Any developer who added them as dependencies could silently install a new remote […]

The post Three Malicious NPM Packages Attacking Developers to Steal Login Credentials appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: