NPM Bug Allowed Attackers to Distribute Malware as Legitimate Packages

A "logical flaw" has been disclosed in NPM, the default package manager for the Node.js JavaScript runtime environment, that enables malicious actors to pass off rogue libraries as legitimate and trick unsuspecting developers into installing them. The supply chain threat has been dubbed "Package Planting" by researchers from cloud security firm Aqua. Following responsible disclosure on February

from The Hacker News https://ift.tt/BKUMNCF
via IFTTT
NPM Bug Allowed Attackers to Distribute Malware as Legitimate Packages NPM Bug Allowed Attackers to Distribute Malware as Legitimate Packages Reviewed by Fully Health Tips And Tricks 2020 on April 26, 2022 Rating: 5

No comments:

Powered by Blogger.