Security News

Cybersecurity news aggregator

⚔️
HIGH Attacks Malpedia

Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer

Hijacked npm packages deploy a credential and cryptocurrency stealer using a novel technique that abuses VSCode's autorun feature for persistence and blockchain-based "dead drops" for command-and-control communication. The article does not provide CVSS scores, specific affected or fixed package version numbers, or explicit workarounds.
Read Full Article →

2026-06-24 (Back to Inventory) Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer Author(s): Guy Korolevski , Yair Benamou Organization: JFrog Security js.jadesnow Open article directly Open article on Archive.org Related Articles 2026-06-22 ⋅ JFrog Security ⋅ Yair Benamou From PostCSS Masquerading to Windows RAT PylangGhost

Share this article