2026-06-24 (Back to Inventory)

Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer

Author(s): Guy Korolevski, Yair Benamou
Organization: JFrog Security
js.jadesnow

Open article directly   Open article on Archive.org  

Related Articles

2026-06-30JFrog SecurityYair Benamou
Lazarus-Linked npm Malware Masquerades as Rollup Polyfills
OtterCookie
2026-06-22JFrog SecurityYair Benamou
From PostCSS Masquerading to Windows RAT
PylangGhost