Security
Headlines
HeadlinesLatestCVEs

Headline

Rogue npm Packages Mimic Telegram Bot API to Plant SSH Backdoors on Linux Systems

Cybersecurity researchers have uncovered three malicious packages in the npm registry that masquerade as a popular Telegram bot library but harbor SSH backdoors and data exfiltration capabilities. The packages in question are listed below -

node-telegram-utils (132 downloads) node-telegram-bots-api (82 downloads) node-telegram-util (73 downloads)

According to supply chain

The Hacker News
#linux#nodejs#backdoor#ssh#The Hacker News

The Hacker News: Latest News

New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs