Source |
HackRead |
Identifiant |
8633077 |
Date de publication |
2025-01-03 11:08:25 (vue: 2025-01-03 12:08:03) |
Titre |
NPM Package Disguised as an Ethereum Tool Deploys Quasar RAT (Recyclage) |
Texte |
Researchers discovered a malicious package on the npm package registry that resembles a library for Ethereum smart contract vulnerabilities but actually drops an open-source remote access trojan called Quasar RAT onto developer systems.
Researchers discovered a malicious package on the npm package registry that resembles a library for Ethereum smart contract vulnerabilities but actually drops an open-source remote access trojan called Quasar RAT onto developer systems. |
Notes |
★★
|
Envoyé |
Oui |
Condensat |
access actually but called contract deploys developer discovered disguised drops ethereum library malicious npm onto open package quasar rat registry remote researchers resembles smart source systems tool trojan vulnerabilities |
Tags |
Tool
Vulnerability
|
Stories |
|
Move |
|
Source |
The Hacker News |
Identifiant |
8632657 |
Date de publication |
2025-01-02 13:15:00 (vue: 2025-01-02 09:07:59) |
Titre |
Malicious Obfuscated NPM Package Disguised as an Ethereum Tool Deploys Quasar RAT |
Texte |
Cybersecurity researchers have discovered a malicious package on the npm package registry that masquerades as a library for detecting vulnerabilities in Ethereum smart contracts but, in reality, drops an open-source remote access trojan called Quasar RAT onto developer systems.
The heavily obfuscated package, named ethereumvulncontracthandler, was published to npm on December 18, 2024, by a user
Cybersecurity researchers have discovered a malicious package on the npm package registry that masquerades as a library for detecting vulnerabilities in Ethereum smart contracts but, in reality, drops an open-source remote access trojan called Quasar RAT onto developer systems.
The heavily obfuscated package, named ethereumvulncontracthandler, was published to npm on December 18, 2024, by a user |
Notes |
★★
|
Envoyé |
Oui |
Condensat |
2024 access but called contracts cybersecurity december deploys detecting developer discovered disguised drops ethereum ethereumvulncontracthandler have heavily library malicious masquerades named npm obfuscated onto open package published quasar rat reality registry remote researchers smart source systems tool trojan user vulnerabilities |
Tags |
Tool
Vulnerability
|
Stories |
|
Move |
|