Open post d33p.js @d33pjs@infosec.exchange · 2mo ago Replying to @hacksilon@infosec.exchange It also never ceases to amaze me that people will compromise a widely used library / service and then ship a highly specific Bitcoin malware instead of a more general infostealer or something like that. If you have that kind of access, why burn it on something dumb? I mean, I guess I'm happy they did, but still. Also, Permission Policy works - on the site I was doing incident response for, the malware was actually blocked by the Permission Policy disabling clipboard access requests. @hacksilon@infosec.exchange PS. I like to add more hashtags to make it easier for people to find your post about malicious adform package. #supplychain #supplychainsecurity #supplychainattack #npm #npmsecurity #ioc