URL has been copied successfully!
Sonatype Discovers Two Malicious npm Packages
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Sonatype Discovers Two Malicious npm Packages

<div cla Text on screen noting two malicious npm packages with the Sonatype Security Research banner at the top of the image

Sonatype Security Research has identified a potential compromise of a trusted npm maintainer account that has now published two malicious npm packages, sbx-mask and touch-adv, designed to exfiltrate secrets from victims’ computers.

First seen on securityboulevard.com

Jump to article: securityboulevard.com/2026/03/sonatype-discovers-two-malicious-npm-packages/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link