Suivre

Douze (12) paquets hébergés sur npmjs.com contiennent du code malveillant.

« Malicious javascript compromise on npmjs.com. These packages, about a billion downloads prior. » ( Kevin Beaumont )

« Make security auditing a part of your routine. » ― « The open-source ecosystem runs on trust, but it's crucial to be vigilant. » [ jdstaerk.substack.com/p/we-jus ]

🛠 How the Malware Works (Step by Step) [ aikido.dev/blog/npm-debug-and- ]

  • Additional backdoored packages : ansi-styles ; debug ; chalk ; supports-color ; strip-ansi ; ansi-regex ; has-ansi

☣️ Shai-Hulud : It includes a self-propagating mechanism that automatically infects downstream packages, creating a cascading compromise across the ecosystem.  [ stepsecurity.io/blog/ctrl-tiny ]

🦠 « A supply chain attack that conducts a supply chain attack. » ( Nicholas Weaver )

Inscrivez-vous pour prendre part à la conversation
nanao

Comme le soleil, les machines ne se couchent jamais.