DiscoverSANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)SANS Stormcast Wednesday, December 3rd, 2025: SmartTube Compromise; NPM Malware Prompt Injection Attempt; Angular XSS Vulnerability
SANS Stormcast Wednesday, December 3rd, 2025: SmartTube Compromise; NPM Malware Prompt Injection Attempt; Angular XSS Vulnerability

SANS Stormcast Wednesday, December 3rd, 2025: SmartTube Compromise; NPM Malware Prompt Injection Attempt; Angular XSS Vulnerability

Update: 2025-12-03
Share

Description



SmartTube Android App Compromise

The key a developer used to sign the Android YouTube player SmartTube was compromised and used to publish a malicious version.

https://github.com/yuliskov/SmartTube/issues/5131#issue-3670629826

https://github.com/yuliskov/SmartTube/releases/tag/notification

Two Years, 17K Downloads: The NPM Malware That Tried to Gaslight Security Scanners

Over the course of two years, a malicious NPM package was updated to evade detection and has now been identified, in part, due to its attempt to bypass AI scanners through prompt injection.

https://www.koi.ai/blog/two-years-17k-downloads-the-npm-malware-that-tried-to-gaslight-security-scanners

Stored XSS Vulnerability via SVG Animation, SVG URL, and MathML Attributes

Angular fixed a store XSS vulnerability.

https://github.com/angular/angular/security/advisories/GHSA-v4hv-rgfq-gp49
Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

SANS Stormcast Wednesday, December 3rd, 2025: SmartTube Compromise; NPM Malware Prompt Injection Attempt; Angular XSS Vulnerability

SANS Stormcast Wednesday, December 3rd, 2025: SmartTube Compromise; NPM Malware Prompt Injection Attempt; Angular XSS Vulnerability

Dr. Johannes B. Ullrich