Crypto Ticker:
sysadmin from Cyber Security News

GHAPPIER Supply Chain Attack Compromises 65 GitHub Repositories and Poisons npm Package

Tushar Subhra Dutta
4 hours ago
2 Views
0 Comments
GHAPPIER Supply Chain Attack Compromises 65 GitHub Repositories and Poisons npm Package

A newly uncovered software supply chain attack has shown how quickly a trusted developer account can become a delivery route for malware. The operation, tracked as GHAPPIER, reached 65 GitHub repositories, infecting 73 files across 22 accounts. It involved a legitimate npm package that distributed a malicious loader to users. Attackers used access to a package maintainer account to alter source code and automate publication from the project’s main branch. The poisoned release appeared legitimate because it was built through the project’s automated publishing process. That made a routine dependency update capable of carrying a remote code loader into developer environments. CloudSEK said in a report shared with Cyber...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!