menu
techminis

A naukri.com initiative

google-web-stories
Home

>

Technology News

>

Popular NP...
source image

Tech Radar

2d

read

194

img
dot

Image Credit: Tech Radar

Popular NPM packages with over a million downloads hit by malware

  • 17 NPM packages with more than a million weekly downloads were compromised to deliver a RAT, potentially impacting a vast number of users.
  • Cybersecurity experts warn of a possible major supply chain attack as malicious code was discovered in popular Gluestack packages.
  • The affected packages, including @react-native-aria and @gluestack-ui, have been deprecated, but users are advised to remain cautious.
  • Access tokens were revoked by Gluestack to prevent further harm, and the compromised tools are marked as deprecated on NPM.

Read Full Article

like

11 Likes

For uninterrupted reading, download the app