17 malicious packages have been identified in the NPM repository.
The NPM repository has identified 17 malicious packages that were distributed using typosquatting, i.e., by assigning names similar to those of popular libraries, anticipating that users would make a typo when typing the name or would overlook the differences while selecting a module from the list. The packages discord-selfbot-v14, discord-lofy, discordsystem, and discord-vilao used a modified version of the legitimate library discord.js, which provides functions for […]
