In The News
September 23, 2022

Dark Reading: Malicious npm Package Poses as Tailwind Tool

ReversingLabs researchers detected the malicious behavior because the purported library modification contained code obfuscated with JavaScript Obfuscator
September 2, 2022

DevOps.com: Supply Chain Security - Has the Next SolarWinds Already Happened?

The SolarWinds incident was the subject of five separate talks and panels at the recent RSA conference in San Francisco
August 8, 2022

SC Media: Windows, Linux ESXi servers targeted by novel GwisinLocker ransomware

ReversingLabs report showed that VMware ESXi virtual machines have been a primary focus for encryption by GwisinLocker's Linux encryptor
August 3, 2022

Dark Reading: School Kid Uploads Ransomware Scripts to PyPI Repository as 'Fun' Project

The malware packages had names that were common typosquats of a legitimate widely used Python library. One was downloaded hundreds of times.
July 14, 2022

Risky Biz News: Malicious npm libraries

ReversingLabs said it found 31 npm libraries that contained obfuscated JavaScript code that would steal web form data
July 14, 2022

The Register: Typo-squatting NPM software supply chain attack uncovered

Researchers at ReversingLabs have uncovered evidence of a widespread software supply chain attack through malicious JavaScript packages picked up via NPM