Analysis conducted by Sonatype revealed the web-browserify package had been created by stitching together hundreds of different open source components, all of which are legitimate when taken in isolation. The package extracts and runs an ELF malware executable, elevating the attacker’s privileges and laying the foundations for all manner of surveillance activities once it has been downloaded. The malware is also able to gain persistence on Linux, building itself into the startup process that activates whenever a device is switched on. which is the safest operating system if nor the two ?

