DSTRYR
@destroyerlabs
Formerly The Nike Destroyer.
ID: 1304934028563410950
13-09-2020 00:05:09
82 Tweet
41 Takipçi
4 Takip Edilen
🚨 Active supply chain attack on [email protected]. The latest version pulls in [email protected] -- a brand-new package that didn't exist before today. Socket's AI analysis flags it as a malicious obfuscated dropper: runtime deobfuscation, dynamic execSync loading, payload
🚨 ACTIVE SUPPLY CHAIN ATTACK Two malicious versions of `axios`, the npm package with 300M+ weekly downloads, were just published via a hijacked maintainer account and have deployed a cross-platform RAT to affected machines. Affected: `[email protected]` and `[email protected]` 👇🧵