menu
techminis

A naukri.com initiative

google-web-stories
Home

>

Malware News

>

Hundreds o...
source image

Arstechnica

1M

read

387

img
dot

Image Credit: Arstechnica

Hundreds of code libraries posted to NPM try to install malware on dev machines

  • An ongoing attack is uploading hundreds of malicious packages to the open source node package manager (NPM) repository.
  • The malicious packages have names that are similar to legitimate ones for code libraries like Puppeteer and Bignum.js.
  • Researchers from the security firm Phylum discovered the campaign, highlighting the prevalence of supply chain attacks.
  • This attack follows a similar campaign a few weeks ago targeting developers using forks of the Ethers.js library.

Read Full Article

like

23 Likes

For uninterrupted reading, download the app