News
Popular JavaScript libraries eslint-config-prettier and eslint-plugin-prettier were hijacked this week and turned into ...
The Register on MSN7d
Not pretty, not Windows-only: npm phishing attack laces popular packages with malwareThe "is" package was infected with cross-platform malware after a scam targeting maintainers The popular npm package "is" was ...
Stylus library and replaced them with a "security holding" page, breaking pipelines and builds worldwide that rely on the ...
It has been a busy week for supply-chain attacks targeting open source software available in public repositories, with ...
In a newly discovered supply chain attack, attackers last week targeted a range of npm-hosted JavaScript type testing ...
Experts have warned that ‘is’, an npm package with more than 2.8 million weekly downloads, was also compromised in the same manner, and served malware for roughly six hours.
Several popular npm packages with millions of weekly downloads were targeted, and one used as a launchpad for malware deployment, when its maintainer fell prey to a phishing attack. JounQin is a ...
Developer freelancing platform Toptal has been inadvertently spreading malicious code after attackers broke into its systems ...
In what's the latest instance of a software supply chain attack, unknown threat actors managed to compromise Toptal's GitHub ...
npm packages hit by phishing-based supply chain attack, exposing developers to malware and remote access threats.
DLL-based malware targets Windows users after a phishing campaign tricked the maintainer into leaking a token.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results