frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Attackers Are Hunting High-Impact Node.js Maintainers with Social Engineering

https://socket.dev/blog/attackers-hunting-high-impact-nodejs-maintainers
2•pier25•1h ago

Comments

bedroom_jabroni•1h ago
Saw the axios post-mortem thread on X and it kept me wondering how the prompt to install an "updated SDK" appeared on the screen - does Zoom provide programmable interactions?

I guess at the end of the day it's just a lookalike phishing link?

VoxPelli•1h ago
“it's just a lookalike phishing link”

In a way, yes, but embedded in a thick thick layer of social engineering