Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing Open-Source Supply Chain Attacks

Several malicious packages have been uncovered across the npm, Python, and Ruby package repositories that drain funds from cryptocurrency wallets, erase entire codebases after installation, and exfiltrate Telegram API tokens, once again demonstrating the variety of supply chain threats lurking in open-source ecosystems.
The findings come from multiple reports published by Checkmarx,

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

HPE Issues Security Patch for StoreOnce Bug Allowing Remote Authentication Bypass

Next Post

Your SaaS Data Isn’t Safe: Why Traditional DLP Solutions Fail in the Browser Era

Related Posts
Total
0
Share