Steganography Attack: Malicious NPM Package Hides Executable Code Inside a QR Code Image
Socket Threat Research has discovered a malicious NPM package named fezbox, published by a user going by janedu. Ostensibly a harmless library, the package conceals an unusually sophisticated payload: it uses a QR code...