News

Due to JavaScript’s small standard library, a great deal of the functionality JavaScript apps rely on is offloaded to third-party libraries.
A hacker has gained (legitimate) access to a popular JavaScript library and has injected malicious code that steals Bitcoin and Bitcoin Cash funds stored inside BitPay's Copay wallet apps.
A JavaScript library that scores over two million downloads every week has been injected with malicious code for stealing coins from a cryptocurrency wallet.
The library, which was listed in NPM’s repository, was then updated with malicious code that contains cryptocurrency-stealing malware. Put another way, Event-Stream was updated to include ...