Malicious npm Packages Distributing BeaverTail Malware Targeting Tech Job Seekers

 Three malicious npm packages—passports-js, bcrypts-js, and blockscan-api—were found to distribute BeaverTail malware, associated with a North Korean campaign targeting U.S. tech job seekers. The malware, a downloader and information stealer, was disguised as part of fictitious job interviews. Despite their removal, these packages had already accumulated over 300 downloads. The incident underscores growing concerns about security within the open-source software supply chain, particularly the exploitation of legitimate packages by malicious actors. 


For more details, visit the full article [here](https://informationsecuritybuzz.com/mal-npm-packages-beavertail-malware/).

Comments

Popular posts from this blog

Endor Labs Announces Integrated SAST Offerings

The Hidden Cost of DevSecOps: Time and Financial Burden of Security on Developers

OWASP Releases Enhanced Dependency-Check Tool with Advanced Tagging and Policy Management Features