Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server.
A malicious npm package reached over 2 million weekly downloads by hiding its payload in a routine library function rather than an install script.
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by ...
2026年9月第三週的資安新聞熱點,聚焦歐盟CRA通報義務上路、AI安全爭議升溫與個資保護監管強化;針對網路、應用程式與端點的漏洞利用攻擊持續頻傳,國內外亦接連傳出企業遭駭,特別是義大利醫療機構遭勒索軟體攻擊造成多項醫療服務中斷近兩週,商周集團網站復 ...