Access Data at Risk: Worm Hijacks NPM Packages with Billions of Downloads
TL;DR
AI-generated
A worm has compromised over 400 NPM packages, totaling more than two billion monthly downloads, to steal developer credentials. Attackers inserted malicious code that intercepts login information for cloud services and other tools.
Source: golem.de
Same event
- Vulnerabilities in WordPress: Ongoing malicious code attacks endanger millions of websites
- Access Data at Risk: Worm Hijacks NPM Packages with Billions of Downloads
- Supply chain attack on keyv: Shai-Hulud worm infects over 440 npm packages
- Supply Chain Attack: Backdoor Inserted into Millions of Downloaded Rust Crates
Discussion
Log in to join the discussion.
No comments yet. Be the first!