Kryptovaluta-ticker:
sysadmin fra Cyber Security News

GHAPPIER Supply Chain Attack Compromises 65 GitHub Repositories and Poisons npm Package

Tushar Subhra Dutta
5 hours ago
3 Visninger
0 Kommentarer
GHAPPIER Supply Chain Attack Compromises 65 GitHub Repositories and Poisons npm Package

A newly uncovered software supply chain attack has shown how quickly a trusted developer account can become a delivery route for malware. The operation, tracked as GHAPPIER, reached 65 GitHub repositories, infecting 73 files across 22 accounts. It involved a legitimate npm package that distributed a malicious loader to users. Attackers used access to a package maintainer account to alter source code and automate publication from the project’s main branch. The poisoned release appeared legitimate because it was built through the project’s automated publishing process. That made a routine dependency update capable of carrying a remote code loader into developer environments. CloudSEK said in a report shared with Cyber...

Læs hele artiklen hos kilden.

Deltag i diskussionen — kommenter, stem og del links.

Registrer
Var dette nyttigt?
Del:

Kommentarer (0)

Log venligst ind eller opret dig for at deltage i diskussionen

Ingen kommentarer ennå. Bli den første til å kommentere!