All CosmicBytez Labs articles tagged #JavaScript, across news, security advisories, how-to guides, and projects.
A critical unpatched flaw in isolated-vm allows sandboxed JavaScript code to escape its isolated environment and achieve host-level remote code execution.
Seroval < 1.5.3 allows attacker-controlled JSON Promise nodes to bypass reference validation in fromJSON(), enabling object forgery. CVSS 9.8.
Security firm Coinspect has identified CryptoJS.lib.WordArray.random() — a 12-year-old weak random number generator — as the root cause behind the Ill Bloom wallet drain incidents, affecting five cryptocurrency wallet applications and resulting in over $5.7 million in losses.
The ChainDrop worm — a larger descendant of the earlier Shai-Hulud attack — has compromised over 1,300 npm packages with a combined 2 billion monthly downloads in under four hours, abusing preinstall hooks, GitHub OIDC trusted publishing, and the Bun runtime to spread.
Online advertising firm Adform suffered a supply-chain attack — a third party compromised Adform's JavaScript ad delivery script to inject clipboard-hijacking code that silently swapped cryptocurrency wallet addresses copied by visitors.
Attackers compromised a JavaScript file served by ad tech company Adform, turning it into a browser-side tool that silently rewrites cryptocurrency wallet addresses to redirect payments to attacker-controlled wallets.
The SourTrade malvertising campaign impersonates Solana, Luno, and TradingView to deliver malware assembled entirely inside browser memory using...
All versions of the expr-eval JavaScript package are vulnerable to remote code execution through the toJSFunction() API. Crafted expressions escape the...
Axios versions 1.7.0 through 1.15.x fail to enforce maxContentLength and maxBodyLength when using the fetch adapter, allowing unbounded request and...
Tech giant Toshiba and mega-retailer Muji have warned visitors that suspicious sign-in screens appearing on their websites could be harvesting credentials — a…
A newly discovered supply chain attack targeting the npm ecosystem steals developer authentication tokens and uses compromised accounts to publish...
A critical remote code execution vulnerability in protobuf.js, the widely used JavaScript implementation of Google's Protocol Buffers, has been disclosed...
Attackers hijacked AppsFlyer's CDN domain via a registrar incident, serving a sophisticated 170 KB crypto-stealing JavaScript payload to every site...
Implement offline data persistence in Progressive Web Apps using IndexedDB. Covers database abstraction, CRUD operations, migration strategies, and sync...
Security researchers have discovered malicious code injected into several popular NPM packages with millions of weekly downloads. Developers urged to...