Story perspectives
Malicious npm Packages Expose Developers to Serious Malware Threats
3/26/2025
50 5
1 of 1
Story summary
- A recent discovery by ReversingLabs reveals a concerning malware campaign exploiting malicious npm packages, notably “ethers-provider2” and “ethers-providerz.” These deceptive packages infiltrate development environments, creating reverse shells and granting attackers ongoing access. With even a few downloads posing a serious risk, this highlights the urgent need for heightened awareness against software supply chain threats.
