Complex Mathematics

Npm package with millions of downloads is at risk from malware hijacking




  • A popular npm maintainer fell prey to a phishing attack, sharing login credentials with cybercriminals
  • The attackers accessed their npm account and pushed malware through a popular package
  • They were removed six hours later, but users should still take caution

Experts have warned that ‘is’, an npm package with more than 2.8 million weekly downloads, was also compromised in the same manner, and served malware for roughly six hours.

This comes shortly after Eslint-config-prettier, another popular npm package, was recently compromised in a supply chain attack which made it serve malware, after its maintainer, JounQin, received an email that spoofed the support@npmjs.com account, asking them to “verify” their account which, when they did, gave the attackers their login credentials.



Source link


Discover more from cplexmath tech stop

Subscribe to get the latest posts sent to your email.

Discover more from cplexmath tech stop

Subscribe now to keep reading and get access to the full archive.

Continue reading