Tagged: npm

RubyGems and npm package typosquatting attack deploying StubMaker stealer 0

Typosquatting Attack Strikes RubyGems and npm

Malicious actors brazenly targeted developers utilizing counterfeit packages deployed simultaneously across two highly prominent repositories. Cybercriminals stealthily introduced 16 malicious libraries into RubyGems and strategically placed another 37 within the npm registry. They meticulously...

Shai-Hulud npm worm architecture and JavaScript supply chain attack payload 0

Shai-Hulud npm Worm Compromises Supply Chain

The Initial JavaScript Breach A single installation of a routine JavaScript library could expose a company’s cloud infrastructure, repositories, and internal services to attackers. The Shai-Hulud npm worm infiltrated highly popular packages. Users download...