Cybersecurity Alert: 8 Malicious NPM Packages Target Windows Chrome Users

Researchers at JFrog Security uncovered eight malicious NPM packages designed to compromise Google Chrome users on Windows. Using 70 layers of code obfuscation, these packages evaded detection and silently installed Python to run hidden scripts that stole passwords, credit card info, crypto wallets, and cookies.


The packages, linked to two NPM accounts named “ruer” and “npjun,” highlight the growing threat of supply chain attacks exploiting open-source repositories through tactics like typosquatting.


JFrog has removed the malicious packages but warns this incident underscores the need for stronger supply chain security and automated scanning to protect developers and users from sophisticated attacks.
NPAV offers a robust solution to combat cyber fraud. Protect yourself with our top-tier security product, Z Plus Security
- Other (43)
- Ransomware (166)
- Events and News (27)
- Features (45)
- Security (493)
- Tips (79)
- Google (35)
- Achievements (12)
- Products (37)
- Activation (7)
- Dealers (1)
- Bank Phishing (56)
- Malware Alerts (256)
- Cyber Attack (332)
- Data Backup (14)
- Data Breach (163)
- Phishing (174)
- Securty Tips (3)
- Browser Hijack (21)
- Adware (15)
- Email And Password (74)
- Android Security (87)
- Knoweldgebase (38)
- Botnet (19)
- Updates (4)
- Alert (71)
- Hacking (76)
- Social Media (9)
- vulnerability (102)
- Hacker (51)
- Spyware (14)
- Windows (12)
- Microsoft (34)
- Uber (1)
- YouTube (2)
- Trojan (7)
- Website hacks (10)
- Paytm (1)
- Credit card scam (4)
- Telegram (5)
- RAT (9)
- Bug (3)
- Twitter (2)
- Facebook (10)
- Banking Trojan (13)
- Mozilla (2)
- COVID-19 (5)
- Instagram (4)
- NPAV Announcement (14)
- IoT Security (3)
- Deals and Offers (2)
- Cloud Security (12)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (3)
- Amazon (3)
- DMart (1)
- Payment Risk (5)
- Occasion (3)
- firewall (4)
- Cloud malware (3)
- Cloud storage (2)
- Financial fraud (79)
- Impersonation phishing (1)
- DDoS (9)
- Smishing (2)
- Whale (0)
- Whale phishing (4)
- WINRAR (3)
- ZIP (2)
- Fraud Protector (67)
-
Mobile Frauds
(29)
- WhatsApp (8)
- AI (7)