<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Node Js</title><description>Cybersecurity articles tagged #Node Js on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Node.js Abuse: Attackers Deploy Malware via Trusted Runtime</title><link>https://runtimerebel.com/blog/node-js-abuse-attackers-deploy-malware-via-trusted-runtime</link><guid isPermaLink="true">https://runtimerebel.com/blog/node-js-abuse-attackers-deploy-malware-via-trusted-runtime</guid><description>Threat actors are leveraging Node.js as a signed, trusted tool to deploy various malicious payloads, evading detection in targeted attacks since February 2026.</description><pubDate>Thu, 03 Sep 2026 12:22:47 GMT</pubDate><category>Node Js</category><category>Malware Delivery</category><category>ClickFix</category><category>Living-off-the-Land</category><category>EtherHiding</category></item><item><title>Critical Type Confusion in isolated-vm Leads to Host RCE</title><link>https://runtimerebel.com/blog/critical-type-confusion-in-isolated-vm-leads-to-host-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-type-confusion-in-isolated-vm-leads-to-host-rce</guid><description>A critical type confusion vulnerability in the Node.js isolated-vm library allows remote code execution on the host system via V8 Isolates.</description><pubDate>Sun, 23 Aug 2026 08:20:33 GMT</pubDate><category>Isolated Vm</category><category>Node Js</category><category>RCE</category><category>Type Confusion</category><category>V8</category></item><item><title>Compromised Joyfill npm Packages Deliver DEV#POPPER RAT</title><link>https://runtimerebel.com/blog/compromised-joyfill-npm-packages-deliver-dev-popper-rat</link><guid isPermaLink="true">https://runtimerebel.com/blog/compromised-joyfill-npm-packages-deliver-dev-popper-rat</guid><description>Beta versions of @joyfill/layouts and @joyfill/components npm packages compromised to deliver a DEV#POPPER RAT upon import. Node.js users at risk.</description><pubDate>Wed, 29 Jul 2026 06:32:18 GMT</pubDate><category>Joyfill</category><category>NPM</category><category>Supply Chain Attack</category><category>RAT</category><category>DEV POPPER</category><category>Node Js</category></item><item><title>North Korean Actors Use SVG Steganography to Deliver OtterCookie</title><link>https://runtimerebel.com/blog/north-korean-actors-use-svg-steganography-to-deliver-ottercookie</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-actors-use-svg-steganography-to-deliver-ottercookie</guid><description>North Korean threat actors are hiding OtterCookie malware in SVG flag images within fake coding tests to target developers and steal cryptocurrency.</description><pubDate>Fri, 17 Jul 2026 17:13:52 GMT</pubDate><category>Lazarus Group</category><category>OtterCookie</category><category>Contagious Interview</category><category>Steganography</category><category>Node Js</category><category>Infostealer</category></item><item><title>Jscrambler npm Package Backdoored with Infostealer Malware</title><link>https://runtimerebel.com/blog/jscrambler-npm-package-backdoored-with-infostealer-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/jscrambler-npm-package-backdoored-with-infostealer-malware</guid><description>A malicious version of the Jscrambler npm package, 5.0.0-beta-1, was backdoored with infostealer malware, affecting 1,500 downloads. Immediate action needed.</description><pubDate>Mon, 13 Jul 2026 20:59:06 GMT</pubDate><category>Jscrambler</category><category>NPM</category><category>Supply Chain Attack</category><category>Infostealer</category><category>Malware</category><category>Node Js</category></item><item><title>npm 12 Security: Default Script Execution Changes to Mitigate Supply Chain Attacks</title><link>https://runtimerebel.com/blog/npm-12-security-default-script-execution-changes-to-mitigate-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/npm-12-security-default-script-execution-changes-to-mitigate-supply-chain-attacks</guid><description>npm 12 introduces a critical change: &apos;npm install&apos; will no longer run dependency scripts by default, significantly reducing software supply chain risks.</description><pubDate>Sat, 13 Jun 2026 16:36:33 GMT</pubDate><category>NPM</category><category>Supply Chain Attack</category><category>Node Js</category><category>Dependency Scripts</category><category>Software Security</category><category>Package Manager</category></item><item><title>Analysis of Cross-Platform NPM Stealer Using Discord Webhooks</title><link>https://runtimerebel.com/blog/analysis-of-cross-platform-npm-stealer-using-discord-webhooks</link><guid isPermaLink="true">https://runtimerebel.com/blog/analysis-of-cross-platform-npm-stealer-using-discord-webhooks</guid><description>Technical teardown of an obfuscated Node.js infostealer targeting Discord tokens, crypto wallets, and browser credentials via cross-platform scripts.</description><pubDate>Fri, 22 May 2026 09:17:57 GMT</pubDate><category>NPM</category><category>Node Js</category><category>Infostealer</category><category>Discord Webhook</category><category>Obfuscation</category></item><item><title>vm2 Node.js Library RCE: Multiple Sandbox Escape Vulnerabilities</title><link>https://runtimerebel.com/blog/vm2-node-js-library-rce-multiple-sandbox-escape-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/vm2-node-js-library-rce-multiple-sandbox-escape-vulnerabilities</guid><description>Discovery of a dozen critical vulnerabilities in the vm2 Node.js library allows for sandbox escape and RCE. Learn how to mitigate these security risks now.</description><pubDate>Thu, 07 May 2026 05:13:20 GMT</pubDate><category>Vm2</category><category>Node Js</category><category>Sandbox Escape</category><category>RCE</category><category>Javascript Security</category></item><item><title>CVE-2023-29017: Critical vm2 Sandbox Escape Leads to Host RCE</title><link>https://runtimerebel.com/blog/cve-2023-29017-critical-vm2-sandbox-escape-leads-to-host-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2023-29017-critical-vm2-sandbox-escape-leads-to-host-rce</guid><description>Technical analysis of CVE-2023-29017 in the vm2 Node.js library. Learn how attackers escape the sandbox for remote code execution and how to patch.</description><pubDate>Wed, 06 May 2026 20:36:13 GMT</pubDate><category>CVE-2023-29017</category><category>Vm2</category><category>Node Js</category><category>Sandbox Escape</category><category>RCE</category></item><item><title>Axios npm Supply Chain Attack: Malicious Payloads and Mitigation</title><link>https://runtimerebel.com/blog/axios-npm-supply-chain-attack-malicious-payloads-and-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/axios-npm-supply-chain-attack-malicious-payloads-and-mitigation</guid><description>Axios npm versions 1.14.1 and 0.30.4 compromised via a malicious dependency injecting remote access trojans. Learn how to detect and remediate this threat.</description><pubDate>Tue, 21 Apr 2026 08:44:16 GMT</pubDate><category>Axios</category><category>NPM</category><category>Node Js</category><category>Plain Crypto Js</category><category>Supply Chain Compromise</category><category>CISA</category></item><item><title>North Korean Social Engineering Targets Node.js Maintainers</title><link>https://runtimerebel.com/blog/north-korean-social-engineering-targets-node-js-maintainers</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-social-engineering-targets-node-js-maintainers</guid><description>North Korean threat actors use social engineering and malicious npm packages to target high-profile Node.js maintainers in a sophisticated supply chain campaign.</description><pubDate>Mon, 06 Apr 2026 12:24:38 GMT</pubDate><category>Lazarus Group</category><category>NPM</category><category>Social Engineering</category><category>Node Js</category><category>North Korea</category></item><item><title>North Korean Malicious npm Packages: Detecting Contagious Interview</title><link>https://runtimerebel.com/blog/north-korean-malicious-npm-packages-detecting-contagious-interview</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-malicious-npm-packages-detecting-contagious-interview</guid><description>North Korean actors published 26 malicious npm packages using Pastebin as a C2 dead drop resolver in a new Contagious Interview campaign iteration.</description><pubDate>Mon, 02 Mar 2026 12:18:05 GMT</pubDate><category>NPM</category><category>Lazarus Group</category><category>Contagious Interview</category><category>Supply Chain Attack</category><category>Pastebin</category><category>C2</category><category>Node Js</category></item></channel></rss>