#node.js


Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Jul 29, 2026 // 07:30

Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER […]

Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant

Jun 26, 2026 // 13:52

An active phishing campaign has been targeting hotel and other hospitality organizations across Europe and Asia since April 2026, using photo-themed ZIP files to drop […]

Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS

Jun 10, 2026 // 10:20

Cybersecurity researchers have flagged half a dozen vulnerabilities in protobuf.js, a JavaScript and TypeScript implementation of Protocol Buffers (Protobuf), that, if successfully exploited, could result […]

vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution

May 7, 2026 // 10:54

A dozen critical security vulnerabilities have been disclosed in the vm2 Node.js library that could be exploited by bad actors to break out of the […]