Cybersecuritynews
Malicious NPM Package Uses Steganography to Deliver .NET Malware
First seen 24 Feb 2026, 15:11 UTC
•
•52.2
Export
Article Content
Browse articles
A malicious NPM package named 'buildrunner-dev' has been discovered to hide .NET malware within PNG images using steganography, allowing it to evade antivirus detection. This attack targets software developers, leveraging a typosquatting technique to deceive users into downloading the harmful package. Upon installation, it executes a script that delivers a Remote Access Trojan to Windows systems.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2026-02-01
Malicious package 'buildrunner-dev' discovered
2026-02-24
Cybersecurity articles published detailing the attack
More articles in this cluster
Continue Reading
Google Addresses Eighth Chrome Zero-Day Vulnerability in 2025
China-linked Cyber Group Expands Targeting to Southeastern Europe
China-Nexus APT UAT-7290 Targets South Asia Telecoms in Cyber Espionage Campaign
China-linked UAT-7290 Targets Telcos in Cyberespionage Campaign
UAT-7290 Cyber Espionage Targets South Asian Telecoms
APT28 Exploits MSHTML Zero-Day Vulnerability in Windows