More

    Compromised files replace npm packages with a combined 2 billion weekly downloads




    • Over a dozen popular npm packages were compromised in a phishing-based supply chain attack
    • The malware targeted crypto users by hijacking wallet addresses during transactions
    • Some called it the most widespread npm compromise to date, affecting 2 billion weekly downloads

    More than a dozen npm packages with two billion downloads a week were compromised in a supply chain attack that targeted cryptocurrency users.

    Researchers at Aikido Security spotted a maintainer account Qix (real name Josh Junon) publishing malicious updates. In less than an hour, multiple versions were uploaded, and soon after Junon himself confirmed the attack and apologized for the mess,

    https://cdn.mos.cms.futurecdn.net/ybiDZeWmV7NsiBqGA5kQy3.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    spot_imgspot_img