Hide and Fail: Obfuscated Malware, Empty Payloads, and npm Shenanigans
aikido.dev | blog | #rce | #supply-chain | #malware | #npm | #obfuscation | #aikido | #eval | #threat-analysis | #npm-malware | #fake-packages | #nodemailer
Summary
npm package node-facebook-messenger-api hid RCE logic behind axios, eval(), and an empty Google Docs payload; the same actor later shipped a fake nodemailer clone with equally conspicuous obfuscation.
- Published
- Collected
Skip to content