event-stream trojan
2018-11-26 21:48:51.235596+00 by Dan Lyke 1 comments
RT Kevin Beaumont 🥴 Verified account @GossiTheDog:
NPM library with 2m installs has a backdoor, looks to be some kind of Trojan (stealer?)
The original author seems to have abandoned the project, someone came along and said they wanted to do something with the project, so: "...he emailed me and said he wanted to maintain the module, so I gave it to him. I don't get any thing from maintaining this module, and I don't even use it anymore, and havn't for years."