ThreatCluster

ShadowPad Attack Exploits WSUS Vulnerability Affecting 25K+ npm Repos

First seen 7 Dec 2025, 20:47 UTC Securityaffairs.Co 29

Article Content

Browse articles
ThreatCluster

The ShadowPad malware attack has exploited a remote code execution vulnerability (CVE-2025-59287) in Windows Server Update Services (WSUS). This incident has exposed over 25,000 npm repositories, allowing cyber threat actors to target users of messaging applications. Morphisec has reported that the attack is linked to Russian cyber operations.