Drooid Logo
Back to today’s briefing

Story perspectives

Malicious npm Packages Expose Developers to Serious Malware Threats

3/26/2025

50 5

1 of 1

Story summary
  • A recent discovery by ReversingLabs reveals a concerning malware campaign exploiting malicious npm packages, notably “ethers-provider2” and “ethers-providerz.” These deceptive packages infiltrate development environments, creating reverse shells and granting attackers ongoing access. With even a few downloads posing a serious risk, this highlights the urgent need for heightened awareness against software supply chain threats.