National Cyber Warfare Foundation (NCWF) Forums


Malicious npm Packages Target Developers' Ethereum Wallets with SSH Backdoor


0 user ratings
2024-10-22 15:43:04
milo
Developers
Cybersecurity researchers have discovered a number of suspicious packages published to the npm registry that are designed to harvest Ethereum private keys and gain remote access to the machine via the secure shell (SSH) protocol.
The packages attempt to "gain SSH access to the victim's machine by writing the attacker’s SSH public key in the root user’s authorized_keys file," software supply



Source: TheHackerNews
Source Link: https://thehackernews.com/2024/10/malicious-npm-packages-target.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Developers



Copyright 2012 through 2024 - National Cyber Warfare Foundation - All rights reserved worldwide.