Malware Injected into 5 npm Packages After Maintainer Tokens Stolen in Phishing Attack

Cybersecurity researchers have alerted to a supply chain attack that has targeted popular npm packages via a phishing campaign designed to steal the project maintainers’ npm tokens.
The captured tokens were then used to publish malicious versions of the packages directly to the registry without any source code commits or pull requests on their respective GitHub repositories.
The list of affected

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

Hackers Exploit Critical CrushFTP Flaw to Gain Admin Access on Unpatched Servers

Next Post

Critical Unpatched SharePoint Zero-Day Actively Exploited, Breaches 75+ Company Servers

Related Posts
Total
0
Share