Crypto Ticker:
sysadmin from Cyber Security News

node-ipc npm Package with 822K Weekly Downloads Compromised in Supply Chain Attack

Guru Baran
6 hours ago
3 Views
0 Comments
node-ipc npm Package with 822K Weekly Downloads Compromised in Supply Chain Attack

A widely used JavaScript inter-process communication library has been weaponized again. Socket and Stepsecurity have confirmed that three newly published versions of node-ipc, a package with over 822,000 weekly downloads, contain obfuscated stealer and backdoor payloads, marking the second major supply chain compromise of this package since...

Read the full article at the source.

Was this helpful?
Share:

Comments (0)

Please login to post a comment

No comments yet. Be the first to comment!