home.social

#jscrambler — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #jscrambler, aggregated by home.social.

fetched live
  1. #JScrambler shares a transparent postmortem on how attackers used a stolen #npm publishing token to ship #malware via its official npm package. A must-read for anyone serious about software supply chain security:

    #SoftwareSupplyChainSecurity
    👇
    jscrambler.com/blog/security-i

  2. #NPM: A compromised release of the popular #JScrambler npm package introduced hidden #malware binaries that execute automatically during npm install, exposing users to a supply chain attack before any application code runs:
    #SoftwareSupplyChainSecurity
    👇
    socket.dev/blog/jscrambler-sup