Three JavaScript packages have been removed from the npm portal for containing malicious code

  • From The Category5.TV Newsroom Episode 665
  • October 21, 2020

Three JavaScript libraries found on the npm portal -- plutov-slack-client, nodetest199 and nodetest1010 -- opened shells on the computers of developers who imported the packages into their projects. The npm security team have removed the package, but are warning users that there is no guarantee this will remove all malicious software resulting from installing it.

This video is provided free of charge. If you enjoy what we do, please consider becoming a Patron so we can continue offering more great content.
Support This Free Content

Discussion

Twitter Posts

Login to Category5

Error message here!

Hide Error message here!

Forgot your password?

Register on Category5

Error message here!

Error message here!

Hide Error message here!

Lost your password? Please enter your email address. You will receive a link to create a new password.

Error message here!

Back to log-in

Close