Security
Headlines
HeadlinesLatestCVEs

Headline

Bogus npm Packages Used to Trick Software Developers into Installing Malware

An ongoing social engineering campaign is targeting software developers with bogus npm packages under the guise of a job interview to trick them into downloading a Python backdoor. Cybersecurity firm Securonix is tracking the activity under the name DEV#POPPER, linking it to North Korean threat actors. "During these fraudulent interviews, the developers are often asked

The Hacker News
#nodejs#backdoor#The Hacker News

The Hacker News: Latest News

Researchers Warn of Privilege Escalation Risks in Google's Vertex AI ML Platform