IT Security News
Cybersecurity news and articles about information security, vulnerabilities, exploits, hacks, laws, spam, viruses, malware, breaches.

Main menu

Skip to content
  • Advertising
  • Contact
  • Legal and Contact information
  • Opt-out preferences
  • Privacy Policy
  • Social Media
    • Apps
    • Telegram Channel
EN, www.infosecurity-magazine.com

Malicious npm Package Masquerades as Popular Email Library

2025-09-02 18:09

A malicious npm package “nodejs-smtp” has been discovered impersonating nodemailer and injecting code to drain crypto wallets

This article has been indexed from www.infosecurity-magazine.com

Read the original article:

Malicious npm Package Masquerades as Popular Email Library

Tags: EN www.infosecurity-magazine.com

Post navigation

← Palo Alto Networks, Zscaler customers impacted by supply chain attacks
New Forensic System Tracks Ghost Guns Made With 3D Printing Using SIDE →

Pages

  • Advertising
  • Contact
  • Legal and Contact information
  • Opt-out preferences
  • Privacy Policy
  • Social Media
    • Apps
    • Telegram Channel

Recent Posts

  • IT Security News Hourly Summary 2025-09-09 21h : 10 posts September 9, 2025
  • Microsoft Patch Tuesday for September 2025 – Snort rules and prominent vulnerabilities September 9, 2025
  • Top 10 Best Internal Network Penetration Testing Providers in 2025 September 9, 2025
  • You can preorder Apple’s new devices this week: iPhone 17, Watch 11, AirPods Pro 3 and more September 9, 2025
  • Apple iPhone 17 Pro Max vs. Samsung Galaxy S25 Ultra: I compared both, and here’s the winner September 9, 2025
  • Is Apple Watch Series 11 worth the upgrade? Here’s how it compares to older models September 9, 2025
  • Apple Events live updates: iPhone 17, iPhone Air, AirPods Pro 3, and new wearables just unveiled September 9, 2025
  • Excited about Apple Watch 11’s hypertension feature? It’s coming to older models too September 9, 2025
  • Quantum Computing Threat Forces Crypto Revolution in 2025 September 9, 2025
  • X’s New Encrypted Chat Has Major Security Flaws Experts Warn September 9, 2025
  • 700M VPN Users at Risk: Hidden Ownership Exposed September 9, 2025
  • Supply chain attack targets npm, +2 Billion weekly npm downloads exposed September 9, 2025
  • Microsoft Patches 86 Vulnerabilities September 9, 2025
  • Microsoft Patch Tuesday September 2025, (Tue, Sep 9th) September 9, 2025
  • Microsoft September 2025 Patch Tuesday – 81 Vulnerabilities and 2 Zero Days Fixed September 9, 2025
  • With Raspberry Pi and Wi-Fi, researchers built a wireless heart rate monitor – here’s how September 9, 2025
  • Billion-Download npm Packages Hijacked in Crypto-Stealing Attack September 9, 2025
  • GitHub Breach Exposed 700+ Companies in Months-Long Attack September 9, 2025
  • Microsoft September 2025 Patch Tuesday – 81 Vulnerabilities Fixed Including 22 RCE September 9, 2025
  • Defense Dept didn’t protect social media accounts, left stream keys out in public September 9, 2025

Copyright © 2025 IT Security News. All Rights Reserved. The Magazine Basic Theme by bavotasan.com.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}