menu
techminis

A naukri.com initiative

google-web-stories
Home

>

Technology News

>

NPM users ...
source image

Tech Radar

4d

read

125

img
dot

Image Credit: Tech Radar

NPM users warned dozens of malicious packages aim to steal host and network data

  • 60 malicious NPM packages identified by cybersecurity researchers Socket stealing sensitive user data and relaying it to attackers with post-install scripts.
  • The malicious packages did not deliver additional malware, escalate privileges, or have persistence mechanisms.
  • The attack involved typosquatting with package names similar to legitimate ones, targeting CI/CD pipelines before being removed after roughly 3,000 downloads.
  • Users advised to remove downloaded malicious packages, run system scans, rotate key credentials, and activate 2FA; separate campaign distributing eight packages capable of causing serious harm also discovered on NPM.

Read Full Article

like

7 Likes

For uninterrupted reading, download the app