NPM packages from Nx targeted in latest worrying software supply chain attack




  • When a token with publishing rights was stolen, multiple poisoned Nx variants were released
  • The malware stole secrets and other important data
  • The attack lasted a few hours, but could be causing damage still

Countless software developers, likely including those within Fortune 500 companies, were victims of a supply chain attack after Nx, the open source build system and development toolkit, was compromised.

In an announcement posted on GitHub, Nx said, “malicious versions of Nx and some supporting plugins were published” on NPM.

https://cdn.mos.cms.futurecdn.net/YbizeHRMkF5QLe6eeYypqc.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img