home.social

#nodepackagemanager — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #nodepackagemanager, aggregated by home.social.

fetched live
  1. Malicious npm packages exploit runtime evasion tactics

    Meet the sneaky npm package that impersonated a popular library, racking up 2 million weekly downloads before revealing its true malicious intent. This cleverly disguised package, indexed-btree, hid its payload in plain sight, masquerading as a legitimate tool until it was too late.

    osintsights.com/malicious-npm-

    #SupplyChain #MaliciousPackages #RuntimeEvasion #Npm #NodePackageManager

  2. North Korea-linked actor compromises axios NPM package

    A shocking discovery by Google Threat Intelligence Group has exposed a vulnerability in the popular axios NPM package, which has over 100 million weekly downloads, and has raised urgent questions about the trustworthiness of software supply chains. A malicious dependency was secretly introduced into axios releases, putting countless…

    osintsights.com/north-korea-li

    #Axios #Npm #NodePackageManager #NorthKorea #GoogleThreatIntelligenceGroup

  3. Always fun when npm’s publish authentication route 404s.

    #NodePackageManager #npm #npmjs #js #node

Share
Share on Mastodon

Enter the server where you have an account.