Kryptovalutaticker:
sysadmin från Cyber Security News

GHAPPIER Supply Chain Attack Compromises 65 GitHub Repositories and Poisons npm Package

Tushar Subhra Dutta
5 hours ago
6 Visningar
0 Kommentarer
GHAPPIER Supply Chain Attack Compromises 65 GitHub Repositories and Poisons npm Package

A newly uncovered software supply chain attack has shown how quickly a trusted developer account can become a delivery route for malware. The operation, tracked as GHAPPIER, reached 65 GitHub repositories, infecting 73 files across 22 accounts. It involved a legitimate npm package that distributed a malicious loader to users. Attackers used access to a package maintainer account to alter source code and automate publication from the project’s main branch. The poisoned release appeared legitimate because it was built through the project’s automated publishing process. That made a routine dependency update capable of carrying a remote code loader into developer environments. CloudSEK said in a report shared with Cyber...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!