npm malware
@npm_malware
📣 We tweet malicious packages detected on npm in real-time. 🚨 Not affiliated with @npmjs or @github. 🛡 Powered by the @SocketSecurity threat feed. ✨
ID: 1564754411540316161
https://socket.dev 30-08-2022 23:18:46
6,6K Tweet
1,1K Followers
11 Following
⚠️ New threat detected: [email protected] ⚠️ The script performs a DNS lookup to a potentially malicious domain that is constructed using the user's username. This behavior raises significant concerns about data exfiltration and telemetry. socket.dev/npm/package/dx…