Security researchers have identified at least 187 npm packages compromised in an ongoing supply chain attack. The coordinated ...
Researchers at Socket, a cybersecurity firm specializing in protection against supply chain attacks, and crypto security ...
What could have been a historic supply chain attack seems to have been averted due to the rapid response of the open source community ...
"Each published package becomes a new distribution vector: as soon as someone installs it, the worm executes, replicates, and ...
Qix is an open source maintainer account that was compromised by a phishing attack. This allowed attackers to infect 18 popular npm packages with malicious code. Together, these packages are ...
Dozens of npm libraries, including a color library with over 2 million downloads a week, have been replaced with novel ...
A new piece of malware is spreading through the popular tinycolor NPM library and more than 300 other packages, some of which ...
Reports surfaced that the widely used npm package @ctrl/tinycolor had been compromised by Wormable Malware as part of a ...
Hardly a week goes by that there isn’t a story to cover about malware getting published to a repository. Last week it was ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results