
Research
NPM targeted by malware campaign mimicking familiar library names
Socket uncovered npm malware campaign mimicking popular Node.js libraries and packages from other ecosystems; packages steal data and execute remote code.
pm2-windows-boot
Advanced tools
[](https://github.com/Zaid-maker/pm2-windows-boot/actions/workflows/node.js.yml) [](https://github.com/Zaid-maker/pm2-windows-boot/actions/workflows/node.js.yml) [ to exfiltrate data and execute commands.