Security
SafeDep discovers encrypted remote access malware in npm's mathmain package
SafeDep publishes full technical analysis with decryption details and indicators
1 Sep 21 10:33 AM · 2d ago · 1 article · 3 posts · 3 sources · development 1 of 1
A detailed write-up shows how the loader works, how to decrypt it, what the payload does, and provides indicators for detection. The analysis reveals no install hooks are present—the password must match matrix data provided by a caller to activate the malware.
“We found a remote access implant hidden inside [email protected], an npm package that copies the popular mathjs library. The malicious code ships encrypted.”
SafeDepSafeDep Security researcher
The whole story articlesposts the bright band is this development · numbered dots are the others · click one to jump
Sep 22yesterdaynow · 2:57 AM ET
Reported in the same hours no headline names this development itself — these 1 claim were published in its stretch
-
first by HN Frontpage, 2d ago
All 1 developments of SafeDep discovers encrypted remote access malware in npm's… →
Hacker NewsMastodonNewswires