Hacker News new | ask | show | jobs
by chalsprhebaodu 909 days ago
A malicious npm package created by the attacker specifically crafted to open up a port that listens and executes commands and otherwise untrusted or unverified code on the victim’s machine.