Blockchain security firm Slow Fog warns of malicious axios releases pulling in plain-crypto-js malware, exposing crypto developers to cross-platform RATs and stolen credentials via npm. The attack involves a fake cryptography package silently added as a new dependency. npm has removed the malicious versions, but environments that pulled them remain at risk.

Leave a Reply