A package called “aabquerys” has been spotted on the open-source JavaScript npm repository using typosquatting techniques to enable the download of malicious components. The findings come from ...
"After detecting several malicious Node Package Manager (NPM) packages in the public NPM registry, a third-party open source ...
The novel malware strain is being dubbed Shai-Hulud — after the name for the giant sandworms in Frank Herbert’s Dune novel ...
Following a number of recent high-profile attacks and hacking attempts, GitHub has decided to make substantial changes to the ...
Hackers planted malicious code in open source software packages with more than 2 billion weekly updates in what is likely to ...
Security researchers have identified at least 187 npm packages compromised in an ongoing supply chain attack. The coordinated ...
In the light of recent supply chain attacks targeting the NPM ecosystem, GitHub will implement tighter authentication and ...
A new digital supply chain attack has targeted popular open-source npm packages with at least two billion downloads per week. On Sept. 8, Josh Junon, a package maintainer whose account was at the ...
In a similar style to the Nx attack, the payload then publishes a new repo via the victim's GitHub account, dropping stolen ...
Hackers injected malicious code into nearly a dozen 20 NPM packages with billions of weekly downloads in a software supply chain attack after phishing a maintainer’s account.
Newly discovered npm package 'fezbox' employs QR codes to hide a second-stage payload to steal cookies from a user's web ...
Results that may be inaccessible to you are currently showing.
Hide inaccessible results