
Malicious NPM Packages Discovered with Hidden Endpoints for System Wiping
SecurityCyberAttacksMalwareBackdoorCyberAttackCybersecurityDevOpsFraudNPMScamSupplyChainVulnerability
Malicious NPM packages have been discovered with hidden endpoints that allow attackers to wipe entire systems on command. Developers are warned to check their dependencies for the packages express-api-sync and system-health-sync-api. These packages contain backdoors that can be activated to cause significant damage to infected systems.