directories

  • Blog

    Malicious npm packages posing as utilities delete project directories

    Two malicious packages have been discovered in the npm JavaScript package index, which masquerades as useful utilities but, in reality, are destructive data wipers that delete entire application directories. The data wiper packages are ‘express-api-sync’ and ‘system-health-sync-api,’ and pose as database syncing and system health monitoring Ttools. According to open-source software security firm Socket, they both contain backdoors that enable…

    Read More »
Back to top button
close