A terrifying, self-replicating malwaere has infected npm packages with over 2 million downloads per week – here’s how to stay safe




  • A new supply-chain attack compromised at least 187 npm packages, targeting developer secrets across software projects
  • Shai-Hulud worm looks to steal credentials, modify packages, and spread malware through GitHub Actions and npm tokens
  • Researchers warn the number of compromised packages is likely to grow

At least 187 malicious npm packages have been uncovered, part of a yet another major supply-chain attack against software developers.

Security researchers from Socket, StepSecurity, and Aikido all detected an ongoing campaign, apparently being orchestrated by the same group that targeted Nx several weeks ago.

https://cdn.mos.cms.futurecdn.net/6UwEJPApAMZKVeWTb8th2V.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img