Source Link A malicious NPM package has been found masquerading as the legitimate software…
npm
-
-
Application SecuritySecurity
OpenSSF releases npm best practices to help developers tackle open-source dependency risks
by Michael Hillby Michael HillSource Link The Open Source Security Foundation (OpenSSF) has released the npm Best Practices…
-
Malware
Malicious npm Packages Used in Siphoning Off Discord Tokens, Card Data
by Deeba Ahmedby Deeba AhmedSource Link The malicious NPM packages used in this supply chain attack can steal…
-
Source Link On July 26, using the internal automated system for monitoring open-source repositories,…
-
Source Link Researchers have disclosed a new large-scale cryptocurrency mining campaign targeting the NPM…
-
Source Link Researchers have disclosed what they say could be an attempt to kick-off…
-
Source Link Researchers have discovered a severe vulnerability in the npm registry that could…
-
Source Link A “logical flaw” has been disclosed in NPM, the default package manager…
-
Source Link A threat actor dubbed “RED-LILI” has been linked to an ongoing large-scale…
-
Application SecuritySecurity
Developer sabotages own npm module prompting open-source supply chain security questions
Source Link The developer of a popular JavaScript component hosted on the npm repository…