⤷ Title: Malicious npm Package Installs Reverse Shell via Payment Success
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 16 Apr 2025 00:26:19 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Malicious Package #npm #reverse shell #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 16 Apr 2025 00:26:19 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Malicious Package #npm #reverse shell #supply chain attack
Daily CyberSecurity
Malicious npm Package Installs Reverse Shell via Payment Success
A malicious npm package, disguised as an Advcash integration, contains a reverse shell that triggers after successful payments, granting attackers server access.
⤷ Title: Typosquatting in Package Managers: The Attack That Preys on a Single Keystroke
════════════════════════
𐀪 Author: InstaTunnel
════════════════════════
ⴵ Time: Sun, 21 Sep 2025 07:55:34 GMT
════════════════════════
⌗ Tags: #malicious_package #typosquatting #package_manager #cybersecurity #supply_chain_attack
════════════════════════
𐀪 Author: InstaTunnel
════════════════════════
ⴵ Time: Sun, 21 Sep 2025 07:55:34 GMT
════════════════════════
⌗ Tags: #malicious_package #typosquatting #package_manager #cybersecurity #supply_chain_attack
Medium
Typosquatting in Package Managers: The Attack That Preys on a Single Keystroke
⤷ Title: First-Ever MCP Supply Chain Attack: Malicious Package Steals Emails by Adding Hidden BCC
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 27 Sep 2025 02:38:23 +0000
════════════════════════
⌗ Tags: #Malware #AI #cybersecurity #Data Theft #Emails #malicious package #MCP #npm #Postmark_mcp #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 27 Sep 2025 02:38:23 +0000
════════════════════════
⌗ Tags: #Malware #AI #cybersecurity #Data Theft #Emails #malicious package #MCP #npm #Postmark_mcp #supply chain attack
Penetration Testing Tools
First-Ever MCP Supply Chain Attack: Malicious Package Steals Emails by Adding Hidden BCC
The npm package postmark-mcp was backdoored to silently forward emails to an external server. The incident shows how Model Context Protocol (MCP) servers are a new supply chain risk.