North Korean XORIndex malware hidden in 67 malicious NPM packages

bleepingcomputer.com

31 points by Bogdanp 17 days ago


owebmaster - 17 days ago

I "got" hacked by a North Korean hacker. I was lucky the dumb virus was meant for Mac and Windows, not Linux. It got installed to my computer but attempted to steal credentials in places there did not exist in my computer, but it was a close call.

After that I never used npm again.

cyanydeez - 17 days ago

North korea and others are likely going if not already, setup an uno reverso and get applicants to do screening tests that require downloading malicious packages.

leggomuhgreggo - 16 days ago

It must be "sanctions renewal" season!

The vipers in the big nest need a bunch of trash cyber security media to premise renewal of sanctions against DPRK.

Bless our patriotic vipers, and their white hat hackers/influencers.

bn-l - 17 days ago

It’s weird how an npm package can just do all this still, to this day.