Kryptovalutaticker:
sysadmin från Cyber Security News

New npm Supply Chain Attack Began with the Keyv Library Compromised Hundreds of Popular Packages

Tushar Subhra Dutta
7 hours ago
7 Visningar
0 Kommentarer
New npm Supply Chain Attack Began with the Keyv Library Compromised Hundreds of Popular Packages

A new npm supply chain attack has turned trusted software packages into a route for credential theft. The campaign began after attackers compromised the maintainer account behind the widely used Keyv library, then used that access to push malicious releases across a growing number of projects. The incident matters because npm packages are routinely installed automatically during development and build work. A poisoned dependency can therefore reach laptops, servers, and automated pipelines without an employee ever visiting a suspicious website or opening a malicious attachment. Microsoft and Socket identified the activity as an active Mini Shai-Hulud campaign, a self-spreading malware operation built to steal access tokens and...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!