Aggregator
Threat Actors Compromise Popular npm Packages to Steal Maintainers’ Tokens
Threat actors have leveraged a phishing campaign targeting npm package maintainers, resulting in the compromise of widely used JavaScript tooling libraries. The campaign, first reported on July 18, 2025, utilizes a typosquatted domain, npnjs.com, to mimic legitimate npm communications and trick developers into surrendering their authentication tokens. This multi-stage operation begins with automated emails scraped […]
The post Threat Actors Compromise Popular npm Packages to Steal Maintainers’ Tokens appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2021-3731 | LedgerSMB clickjacking (Nessus ID 242338)
CVE-2021-3693 | LedgerSMB URL cross site scripting (Nessus ID 242338)
CVE-2021-3694 | LedgerSMB Error Message cross site scripting (Nessus ID 242338)
CVE-2022-40146 | Oracle Fusion Middleware MapViewer 12.2.1.4.0 Install information disclosure (Nessus ID 242417)
CVE-2022-40146 | Oracle Financial Services Revenue Management and Billing up to 4.0 Infrastructure information disclosure (Nessus ID 242417)
CVE-2022-38648 | Apache XML Graphics Batik 1.14 server-side request forgery (Nessus ID 242417)
CVE-2022-38398 | Apache XML Graphics Batik 1.14 JAR Protocol server-side request forgery (Nessus ID 242417)
CVE-2022-40146 | Apache XML Graphics Batik 1.14 JAR URL server-side request forgery (Nessus ID 242417)
CVE-2022-40146 | Oracle Communications MetaSolv Solution 6.3.1 Utilities information disclosure (Nessus ID 242417)
CVE-2020-11987 | Oracle Middleware Common Libraries and Tools 12.2.1.4.0 Third Party Patch input validation (Nessus ID 242417)
CVE-2020-11987 | Oracle Insurance Policy Administration Operational Data Store for Life and Annuity Logger input validation (Nessus ID 242417)
Beware of npm Phishing Emails Targeting Developer Credentials
An developer recently came across a highly advanced phishing email that spoofs the [email protected] address in order to impersonate npm, the Node.js package registry. The email directed recipients to a malicious link on npnjs.com, a domain cleverly typosquatted to mimic npmjs.com by swapping ‘m’ for ‘n’. This fake site hosted a complete clone or proxy […]
The post Beware of npm Phishing Emails Targeting Developer Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.