More

    Thousands of fake packages flood npm registry in major attack – here’s what we know



    • Over 43,000 dormant spam packages flooded npm in a coordinated two-year campaign
    • Some packages contained worm-like scripts that auto-generated and published new entries
    • Attackers may have faked TEA impact scores to earn decentralized developer rewards

    Roughly 1% of the entire npm ecosystem now consists of bogus, dormant packages that were uploaded as part of a years-long targeted – and potentially malicious – campaign, experts have claimed.

    Cybersecurity researchers Endor Labs discovered more than 43,000 spam packages which took almost two years to upload in a coordinated effort that took at least 11 distinct user accounts to pull off.


    https://cdn.mos.cms.futurecdn.net/Ff7Dszi85SiGJuRKiyKZwg-970-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    spot_imgspot_img