MAL-2024-10289
Dashboard / Malicious Package / MAL-2024-10289
MAL-2024-10289
Summary: Malicious code in node-dlls (npm)
Details: The package contains code to download and execute an infostealer payload.
References: https://socket.dev/blog/roblox-developers-targeted-with-npm-packages-infected-with-infostealers, https://security.snyk.io/vuln/SNYK-JS-NODEDLLS-8366345, https://thehackernews.com/2024/11/malicious-npm-packages-target-roblox.html
Affected packages
Package
Name: node-dlls
Purl: pkg:npm/node-dlls
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
1.0.0
