URL has been copied successfully!
Malicious npm Package Leverages Unicode Steganography, Google Calendar as C2 Dropper
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Malicious npm Package Leverages Unicode Steganography, Google Calendar as C2 Dropper

Cybersecurity researchers have discovered a malicious package named “os-info-checker-es6” that disguises itself as an operating system information utility to stealthily drop a next-stage payload onto compromised systems.”This campaign employs clever Unicode-based steganography to hide its initial malicious code and utilizes a Google Calendar event short link as a dynamic dropper for its final

First seen on thehackernews.com

Jump to article: thehackernews.com/2025/05/malicious-npm-package-leverages-unicode.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link