Tagged: Developer Security

Poisoned Packages: A New Attack Hits the npm Ecosystem

Researchers at Socket have disclosed a new attack against the npm ecosystem, in which more than 40 packages were discovered to be laced with embedded malicious code. The compromise mechanism was meticulously engineered: it...