The activity begins with the attackers distributing malicious VBS files via WhatsApp messages that, when executed, create ...
A malware campaign uses WhatsApp messages to deliver VBS scripts that initiate a multi-stage infection chain. The attack ...
A WhatsApp spokesperson declined to answer The Register’s specific questions about this campaign. They did remind users of ...
Axios 1.14.1 and 0.30.4 injected malicious plain-crypto-js@4.2.1 after npm compromise on March 31, 2026, deploying ...
On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages ...
Microsoft warns of a malware campaign that delivers malicious software via WhatsApp messages and compromises systems.
With almost 175,000 npm projects listing the library as a dependency, the attack had a huge cascade effect and shows how ...
Developers using the axios package from npm may have downloaded a malicous version that drops a Remote Access Trojan ...
Two versions of the widely used JavaScript library axios were maliciously published on npm on March 31, 2026. A hijacked ...
�� CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls ...
Overview On March 31, NSFOCUS CERT detected that the npm repository of the HTTP client library Axios was poisoned by the supply chain. The attacker bypassed the normal GitHub Actions CI/CD pipeline of ...
一些您可能无法访问的结果已被隐去。
显示无法访问的结果