⤷ Title: 8 Malicious NPM Packages Stole Chrome User Data on Windows
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 20:00:42 +0000
════════════════════════
⌗ Tags: #Security #Malware #Browser #Chrome #Cyber Attack #Cybersecurity #JFrog #NPM #Supply Chain #Typosquatting
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 20:00:42 +0000
════════════════════════
⌗ Tags: #Security #Malware #Browser #Chrome #Cyber Attack #Cybersecurity #JFrog #NPM #Supply Chain #Typosquatting
Hackread
8 Malicious NPM Packages Stole Chrome User Data on Windows
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Backdoor Disguised as SOCKS5 Proxy: Malicious PyPI Package SoopSocks Grants Root Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 01 Oct 2025 03:01:21 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #cybersecurity #JFrog #PyPI #SOCKS5 #SoopSocks #supply chain attack #Windows Service
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 01 Oct 2025 03:01:21 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #cybersecurity #JFrog #PyPI #SOCKS5 #SoopSocks #supply chain attack #Windows Service
Daily CyberSecurity
Backdoor Disguised as SOCKS5 Proxy: Malicious PyPI Package SoopSocks Grants Root Access
The malicious PyPI package SoopSocks masqueraded as a SOCKS5 proxy but secretly installed a Go-based backdoor with SYSTEM privileges, leaking system data to a Discord webhook.
⤷ Title: Automation or Infiltration? The JFrog Discoveries Breaking n8n’s Security Sandboxes
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 07:42:45 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2026_0863 #CVE_2026_1470 #JavaScript eval injection #JFrog Security #n8n #Ni8mare #python_task_executor #RCE vulnerability #Sandbox Escape #workflow automation security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 07:42:45 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2026_0863 #CVE_2026_1470 #JavaScript eval injection #JFrog Security #n8n #Ni8mare #python_task_executor #RCE vulnerability #Sandbox Escape #workflow automation security
Penetration Testing Tools
Automation or Infiltration? The JFrog Discoveries Breaking n8n’s Security Sandboxes
A team of cybersecurity experts has unearthed two critically severe vulnerabilities within the n8n workflow automation platform. Both
⤷ Title: Supply Chains in the Crosshairs: Scan and Simulate Multi-Stage Attacks with Trajan
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 May 2026 08:24:29 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Azure DevOps #CI/CD Security #DevSecOps #GitHub Actions #GitLab CI #jenkins #JFrog #Pentesting Tools #supply chain attack #Taint Tracking #Trajan #WebAssembly
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 May 2026 08:24:29 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Azure DevOps #CI/CD Security #DevSecOps #GitHub Actions #GitLab CI #jenkins #JFrog #Pentesting Tools #supply chain attack #Taint Tracking #Trajan #WebAssembly
Penetration Testing Tools
Supply Chains in the Crosshairs: Scan and Simulate Multi-Stage Attacks with Trajan
Trajan isn't just a scanner. It maps dependency graphs and uses built-in attack plugins to simulate real-world CI/CD supply chain compromises.
⤷ Title: Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 24 Jun 2026 13:26:36 +0000
════════════════════════
⌗ Tags: #Security #Malware #Chrome #Cyber Attack #Cybersecurity #JFrog #NPM #Password #PostCSS #RAT #Scam #security #Windows
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 24 Jun 2026 13:26:36 +0000
════════════════════════
⌗ Tags: #Security #Malware #Chrome #Cyber Attack #Cybersecurity #JFrog #NPM #Password #PostCSS #RAT #Scam #security #Windows
Hackread
Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords
JFrog warns of malicious npm packages that mimic PostCSS tooling, drop a Windows RAT, and target Chrome-stored passwords through a staged infection setup route.
⤷ Title: Lazarus-Linked npm Malware Masquerades as Rollup Polyfills
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 09:22:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #crypto wallet theft #JFrog #Lazarus #malicious npm packages #North Korea #npm malware #Rollup polyfill #supply chain attack
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 09:22:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #crypto wallet theft #JFrog #Lazarus #malicious npm packages #North Korea #npm malware #Rollup polyfill #supply chain attack
Daily CyberSecurity
Lazarus-Linked npm Malware Masquerades as Rollup Polyfills
At a glance Actor Suspected North Korean Lazarus-linked group (attribution by TTP similarity) Activity npm supply chain attack using lookalike Rollup polyfill packages Targets JavaScript developer…
⤷ Title: Fake AI CVE Reports Expose System Flaws
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 06 Aug 2026 04:19:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #Artificial intelligence #CVE #cybersecurity #JFrog #SQLite
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 06 Aug 2026 04:19:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #Artificial intelligence #CVE #cybersecurity #JFrog #SQLite
Information Security News
Fake AI CVE Reports Expose System Flaws
The Emergence of Fabricated Vulnerabilities Vulnerability databases recently received reports of critical SQLite flaws. These fictitious vulnerabilities boasted severity scores reaching a staggeri…