Skip to main content
← All Articles

Tag

#Node Js

12 articles

Advertisement

Node.js Abuse: Attackers Deploy Malware via Trusted Runtime
MEDIUM
Threat Intel

Node.js Abuse: Attackers Deploy Malware via Trusted Runtime

Threat actors are leveraging Node.js as a signed, trusted tool to deploy various malicious payloads, evading detection in targeted attacks since February 2026.

Runtime Rebel Intel
4 min read · Sep 3, 2026
HIGH
Vulnerabilities

Critical Type Confusion in isolated-vm Leads to Host RCE

A critical type confusion vulnerability in the Node.js isolated-vm library allows remote code execution on the host system via V8 Isolates.

Runtime Rebel Intel
4 min read · Aug 23, 2026
Compromised Joyfill npm Packages Deliver DEV#POPPER RAT
HIGH
Supply Chain

Compromised Joyfill npm Packages Deliver DEV#POPPER RAT

Beta versions of @joyfill/layouts and @joyfill/components npm packages compromised to deliver a DEV#POPPER RAT upon import. Node.js users at risk.

Runtime Rebel Intel
5 min read · Jul 29, 2026
North Korean Actors Use SVG Steganography to Deliver OtterCookie
HIGH
Threat Intel

North Korean Actors Use SVG Steganography to Deliver OtterCookie

North Korean threat actors are hiding OtterCookie malware in SVG flag images within fake coding tests to target developers and steal cryptocurrency.

Runtime Rebel Intel
5 min read · Jul 17, 2026
HIGH
Supply Chain

Jscrambler npm Package Backdoored with Infostealer Malware

A malicious version of the Jscrambler npm package, 5.0.0-beta-1, was backdoored with infostealer malware, affecting 1,500 downloads. Immediate action needed.

Runtime Rebel Intel
4 min read · Jul 13, 2026
INFO
Supply Chain

npm 12 Security: Default Script Execution Changes to Mitigate Supply Chain Attacks

npm 12 introduces a critical change: 'npm install' will no longer run dependency scripts by default, significantly reducing software supply chain risks.

Runtime Rebel Intel
4 min read · Jun 13, 2026

Advertisement

HIGH
Malware

Analysis of Cross-Platform NPM Stealer Using Discord Webhooks

Technical teardown of an obfuscated Node.js infostealer targeting Discord tokens, crypto wallets, and browser credentials via cross-platform scripts.

Runtime Rebel Intel
4 min read · May 22, 2026
vm2 Node.js Library RCE: Multiple Sandbox Escape Vulnerabilities
CRITICAL
Vulnerabilities

vm2 Node.js Library RCE: Multiple Sandbox Escape Vulnerabilities

Discovery of a dozen critical vulnerabilities in the vm2 Node.js library allows for sandbox escape and RCE. Learn how to mitigate these security risks now.

Runtime Rebel Intel
4 min read · May 7, 2026
HIGH
Vulnerabilities

CVE-2023-29017: Critical vm2 Sandbox Escape Leads to Host RCE

Technical analysis of CVE-2023-29017 in the vm2 Node.js library. Learn how attackers escape the sandbox for remote code execution and how to patch.

Runtime Rebel Intel
3 min read · May 6, 2026
HIGH
Supply Chain

Axios npm Supply Chain Attack: Malicious Payloads and Mitigation

Axios npm versions 1.14.1 and 0.30.4 compromised via a malicious dependency injecting remote access trojans. Learn how to detect and remediate this threat.

Runtime Rebel Intel
4 min read · Apr 21, 2026
HIGH
Supply Chain

North Korean Social Engineering Targets Node.js Maintainers

North Korean threat actors use social engineering and malicious npm packages to target high-profile Node.js maintainers in a sophisticated supply chain campaign.

Runtime Rebel Intel
3 min read · Apr 6, 2026
North Korean Malicious npm Packages: Detecting Contagious Interview
HIGH
Supply Chain

North Korean Malicious npm Packages: Detecting Contagious Interview

North Korean actors published 26 malicious npm packages using Pastebin as a C2 dead drop resolver in a new Contagious Interview campaign iteration.

Runtime Rebel Intel
4 min read · Mar 2, 2026