Story perspectives
60 Malicious npm Packages Target User Data Theft
5/27/2025
48 5
1 of 1
Story summary
- A shocking revelation has emerged: 60 malicious npm packages were found, crafted to steal sensitive user data like IP addresses and DNS servers. With over 3,000 downloads, these dangerous packages were tied to three accounts that have since been removed. Meanwhile, harmful extensions in Microsoft's Visual Studio Code Marketplace have also targeted cryptocurrency wallets, underscoring the relentless nature of cybersecurity threats.
