Three years, 37,000 downloads for one package, and three of them are still installable
2026-10-07Security
Checkmarx has documented an npm campaign running since August 2023 that delivered a remote access trojan and an information stealer through twelve packages. What kept it alive is not stealth. It is that the advisory databases security tooling reads never caught up, and three of the packages are still there.