Live data from Hacker News

Attackers Are Hunting High-Impact Node.js Maintainers with Social Engineering

socket.dev

1–3 of 3 posts

Re: Attackers Are Hunting High-Impact Node.js Maintainers with Social Engineering

#2
Saw the axios post-mortem thread on X and it kept me wondering how the prompt to install an "updated SDK" appeared on the screen - does Zoom provide programmable interactions?

I guess at the end of the day it's just a lookalike phishing link?

Re: Attackers Are Hunting High-Impact Node.js Maintainers with Social Engineering

#3

Saw the axios post-mortem thread on X and it kept me wondering how the prompt to install an "updated SDK" appeared on the screen - does Zoom provide programmable interactions? I guess at the end of the day it's just a lookalike phishing link?

“it's just a lookalike phishing link”

In a way, yes, but embedded in a thick thick layer of social engineering