NPM

Cyber security

Attackers Flood NPM Repository with Over 15,000 Spam Packages Containing Phishing Links

[ad_1] Feb 22, 2023Ravie LakshmananOpen Source / Supply Chain Attack In what’s a continuing assault on the open source ecosystem,…

Read More »
Cyber security

Researchers Hijack Popular NPM Package with Millions of Downloads

[ad_1] Feb 16, 2023Ravie LakshmananSupply Chain / Software Security A popular npm package with more than 3.5 million weekly downloads…

Read More »
Cyber security

Researchers Find a Way Malicious NPM Libraries Can Evade Vulnerability Detection

[ad_1] New findings from cybersecurity firm JFrog show that malware targeting the npm ecosystem can evade security checks by taking…

Read More »
Cyber security

New Timing Attack Against NPM Registry API Could Expose Private Packages

[ad_1] A novel timing attack discovered against the npm’s registry API can be exploited to potentially disclose private packages used…

Read More »
Technology

A whole host of crypto npm packages have been compromised

[ad_1] A number of npm packages published by a major cryptocurrency exchange have been compromised and updated to carry malicious…

Read More »
Cyber security

Malicious NPM Package Caught Mimicking Material Tailwind CSS Package

[ad_1] A malicious NPM package has been found masquerading as the legitimate software library for Material Tailwind, once again indicating…

Read More »
Technology

GitHub partners with code-signing service Sigstore to add support for signing npm software packages, helping improve the security of open source projects (Lily Hay Newman/Wired)

[ad_1] Lily Hay Newman / Wired: GitHub partners with code-signing service Sigstore to add support for signing npm software packages,…

Read More »
Cyber security

Nearly 100,000 NPM Users’ Credentials Stolen in GitHub OAuth Breach

[ad_1] Cloud-based repository hosting service GitHub on Friday shared additional details into the theft of GitHub integration OAuth tokens last…

Read More »
Cyber security

NPM Bug Allowed Attackers to Distribute Malware as Legitimate Packages

[ad_1] A “logical flaw” has been disclosed in NPM, the default package manager for the Node.js JavaScript runtime environment, that…

Read More »
Technology

GitHub says an attacker used stolen OAuth user tokens issued to Heroku and Travis-CI to download data from private repositories belonging to npm and other orgs (Sergiu Gatlan/BleepingComputer)

[ad_1] Sergiu Gatlan / BleepingComputer: GitHub says an attacker used stolen OAuth user tokens issued to Heroku and Travis-CI to…

Read More »
Back to top button
Close