Добавить новость
ru24.net
News in English
Ноябрь
2024

Hundreds of code libraries posted to NPM try to install malware on dev machines

0

An ongoing attack is uploading hundreds of malicious packages to the open source node package manager (NPM) repository in an attempt to infect the devices of developers who rely on code libraries there, researchers said.

The malicious packages have names that are similar to legitimate ones for the Puppeteer and Bignum.js code libraries and for various libraries for working with cryptocurrency. The campaign, which was active at the time this post was going live on Ars, was reported by researchers from the security firm Phylum. The discovery comes on the heels of a similar campaign a few weeks ago targeting developers using forks of the Ethers.js library.

Beware of the supply chain attack

“Out of necessity, malware authors have had to endeavor to find more novel ways to hide intent and to obfuscate remote servers under their control,” Phylum researchers wrote. “This is, once again, a persistent reminder that supply chain attacks are alive and well.”

Read full article

Comments




Moscow.media
Частные объявления сегодня





Rss.plus




Спорт в России и мире

Новости спорта


Новости тенниса
WTA

Казанская теннисистка Полина Кудерметова уступила Арине Соболенко в финале WTA в Брисбене






Алкоголь в России снова подорожает: эксперты объясняют причины

В партии Шольца перепутали немецкую подводную лодку с российской

"А не надо было русских кидать": нефтяники из КНР бегут от Запада как от чумы

В Санкт-Петербурге госпитализировали пенсионерку, которая загорелась от плиты