Back to Home

The malicious npm package named crypto-encrypt-ts, which masqueraded as a legitimate revival of the widely used CryptoJS library, accumulated nearly 1,928 downloads before analysis revealed its stealthy, data-harvesting nature.

July 8, 2025

Source

View Original Report

Published on 7/8/2025

Share or Copy this stat

Want More Statistics Like This?

Get the latest cybersecurity stats delivered to your inbox every week

Related Statistics

Browse more stats from Sonatype or explore Open source

Stay Ahead of Cyber Threats

Join 1,000+ security professionals getting weekly insights