CyberHighReportedAccelerating
7.1
Sophisticated Malicious npm Packages Evade Defenses; Possible Nation-State Origin
Schneier on SecurityLO·3 days ago
The domain 'third-party.com', widely used as a placeholder in dev docs, now hosts a fake Cloudflare check that prompts Windows users to run PowerShell, delivering ClickFix malware. This is a novel supply-chain style attack vector targeting developers and IT staff who copy-paste commands from documentation. The scale of exposure is uncertain but potentially broad given the domain's ubiquity in code examples.