National Cyber Warfare Foundation (NCWF)

Malicious npm Package Leverages Unicode Steganography, Google Calendar as C2 Dropper


0 user ratings
2025-05-15 10:40:55
milo
Blue Team (CND) , Attacks
Cybersecurity researchers have discovered a malicious package named "os-info-checker-es6" that disguises itself as an operating system information utility to stealthily drop a next-stage payload onto compromised systems.
"This campaign employs clever Unicode-based steganography to hide its initial malicious code and utilizes a Google Calendar event short link as a dynamic dropper for its final



Source: TheHackerNews
Source Link: https://thehackernews.com/2025/05/malicious-npm-package-leverages-unicode.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)
Attacks



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.