home.social

#nodepackagemanager — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #nodepackagemanager, aggregated by home.social.

  1. North Korea-linked actor compromises axios NPM package

    A shocking discovery by Google Threat Intelligence Group has exposed a vulnerability in the popular axios NPM package, which has over 100 million weekly downloads, and has raised urgent questions about the trustworthiness of software supply chains. A malicious dependency was secretly introduced into axios releases, putting countless…

    osintsights.com/north-korea-li

    #Axios #Npm #NodePackageManager #NorthKorea #GoogleThreatIntelligenceGroup