Kryptovaluta-ticker:
sysadmin fra The Register

Amazon links four poisoned npm packages to one North Korean crew

Thursday at 13:13
10 Visninger
0 Kommentarer
Amazon links four poisoned npm packages to one North Korean crew

Amazon has linked the compromises of four npm packages over the past 18 months, saying they were all the work of the same North Korean crew. In research published this week, AWS attributed the activity with medium confidence to the North Korea-linked group tracked as Sapphire Sleet, which is widely regarded as a Lazarus Group offshoot. Rather than exploiting zero-days or hacking npm itself, the crew allegedly took the slower route of befriending maintainers, stealing credentials, and publishing poisoned updates from accounts that developers already trusted. The research revisits the compromises of typo-crypto, chalk and debug, and Axios, concluding that the four packages were targeted by the same North Korean operation. Google had already...

Læs hele artiklen hos kilden.

Deltag i diskussionen — kommenter, stem og del links.

Registrer
Var dette nyttigt?
Del:

Kommentarer (0)

Log venligst ind eller opret dig for at deltage i diskussionen

Ingen kommentarer ennå. Bli den første til å kommentere!