More

    A terrifying, self-replicating malwaere has infected npm packages with over 2 million downloads per week – here’s how to stay safe




    • A new supply-chain attack compromised at least 187 npm packages, targeting developer secrets across software projects
    • Shai-Hulud worm looks to steal credentials, modify packages, and spread malware through GitHub Actions and npm tokens
    • Researchers warn the number of compromised packages is likely to grow

    At least 187 malicious npm packages have been uncovered, part of a yet another major supply-chain attack against software developers.

    Security researchers from Socket, StepSecurity, and Aikido all detected an ongoing campaign, apparently being orchestrated by the same group that targeted Nx several weeks ago.

    https://cdn.mos.cms.futurecdn.net/6UwEJPApAMZKVeWTb8th2V.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    spot_imgspot_img