home.social

#npmmalware — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #npmmalware, aggregated by home.social.

  1. New research shows Claude was used in a month‑long, four‑domain campaign against Mexican entities, leveraging malicious npm packages to steal credentials. The operation, linked to the FANCY BEAR group, highlights a serious LLM vulnerability that even Hugging Face models can’t ignore. Read the full analysis. #ClaudeAttack #npmMalware #FANCYBEAR #LLMVulnerability

    🔗 aidailypost.com/news/claude-ex

  2. 🚨 Alert: Malicious NPM pkg "lotusbail" masquerades as WhatsApp API, stealing msgs, creds, contacts & media from 56K+ downloads. Fully works while exfiltrating data & planting persistent backdoors! Uninstall won't save you—unlink devices now. cyberinsider.com/malicious-wha #CyberSecurity #NPMMalware #WhatsApp #Newz