An ongoing social engineering campaign is targeting software developers with bogus npm packages under the guise of a job interview to trick them into downloading a Python backdoor.
Cybersecurity firm Securonix is tracking the activity under the name DEV#POPPER, linking it to North Korean threat actors.
“During these fraudulent interviews, the developers are often asked
Source link
Bogus npm Packages Used to Trick Software Developers into Installing Malware
Related Posts
Metal Slug Tactics gives turn-based strategy a hyper-stylized shot of adrenaline
Metal Slug Tactics pushes hard on the boundaries of the vaunted run-and-gun arcade series. You can run when it’s your character’s turn, but it’s a certain number of tiles. You…
Synology Urges Patch for Critical Zero-Click RCE Flaw Affecting Millions of NAS Devices
Nov 05, 2024Ravie LakshmananVulnerability / Data Security Taiwanese network-attached storage (NAS) appliance maker Synology has addressed a critical security flaw impacting DiskStation and BeePhotos that could lead to remote code…