
Ethereum contracts push malware on npm
RL discovered how the crypto contracts were abused — and how this incident is tied to a larger campaign to promote malicious packages on top repositories.

Software Threat Researcher, ReversingLabs. Lucija works on the TitaniumCore Team.
find Lucija Valentić on:

RL discovered how the crypto contracts were abused — and how this incident is tied to a larger campaign to promote malicious packages on top repositories.

RL has discovered a loophole on VS Code Marketplace that allows threat actors to reuse legitimate, removed package names for malicious purposes.

RL researchers have identified yet another npm package that uses malicious patching of local software to hijack cryptocurrency transfers.

For the first time, RL researchers discover malicious locally-installed npm packages infecting other legitimate packages.

To avoid compromised packages being introduced as a dependency in a larger project, security teams need to keep an eye peeled for such malicious code.

Three versions of the popular package were infected and used to spread malicious code that was stealing crypto wallet assets.

The history of the package is a lesson in why tracking open source threats is such a challenge — and highlights the value of RL's new Spectra Assure Community.

Two newly discovered extensions on the VS Code Marketplace are designed to steal sensitive information, showing that open source attacks are expanding.

ReversingLabs researchers found two suspicious npm packages that demonstrate how GitHub is increasingly being used to easily deploy malware in novel ways.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial