SBN

npm packages spread ‘Bladeroid’ crypto-stealer, hijack your Instagram

Sonatype has identified multiple open source packages named sniperv1, sniperv2, among others that infect npm developers with a Windows info-stealer and crypto-stealer called ‘Bladeroid.’

*** This is a Security Bloggers Network syndicated blog from Sonatype Blog authored by Ax Sharma. Read the original post at: https://blog.sonatype.com/npm-packages-caught-spreading-bladeroid-info-stealer