Software Supply Chain

关注

Thousands of fake packages have inundated the npm registry, signaling a major cyber attack. The campaign appears to be preparing for a larger malicious operation, according to security reports. This incident highlights ongoing vulnerabilities in open-source software ecosystems.

由 AI 报道

Security firm Socket has uncovered ten malicious packages in the npm repository that target developers on Windows, macOS, and Linux systems. These packages, available since July, use typosquatting and sophisticated obfuscation to install infostealer malware. The malware steals credentials from browsers, SSH keys, and configuration files before exfiltrating data to attackers.

此网站使用 cookie

我们使用 cookie 进行分析以改进我们的网站。阅读我们的 隐私政策 以获取更多信息。
拒绝