Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

You're Invited: Delivering malware via Google Calendar invites and PUAs

Summary

Aikido found npm package os-info-checker-es6 hiding malicious logic behind Unicode Private Use Area characters, decoded by a native binary into base64 for eval() to execute, evading code review.
Published
Collected

original ↗

Related coverage

back