Rogue npm Packages Mimic Telegram Bot API to Plant SSH Backdoors on Linux Systems

Cybersecurity researchers have uncovered three malicious packages in the npm registry that masquerade as a popular Telegram bot library but harbor SSH backdoors and data exfiltration capabilities.
The packages in question are listed below –

node-telegram-utils (132 downloads)
node-telegram-bots-api (82 downloads)
node-telegram-util (73 downloads)

According to supply chain

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

ASUS Confirms Critical Flaw in AiCloud Routers; Users Urged to Update Firmware

Next Post

APT29 Deploys GRAPELOADER Malware Targeting European Diplomats Through Wine-Tasting Lures

Related Posts
Total
0
Share