Tagged: npm

Cross-platform sckit worm infection vector bridging npm and PyPI ecosystems via MemTensor packages 0

The ‘sckit’ Worm Bridges the npm and PyPI Divide

An identical, highly sophisticated malicious program has successfully breached both sides of a major programming language divide simultaneously. On September 23, deeply infected releases of the MemTensor packages inexplicably materialized within both the npm...

RubyGems and npm package typosquatting attack deploying StubMaker stealer 0

Typosquatting Attack Strikes RubyGems and npm

Malicious actors brazenly targeted developers utilizing counterfeit packages deployed simultaneously across two highly prominent repositories. Cybercriminals stealthily introduced 16 malicious libraries into RubyGems and strategically placed another 37 within the npm registry. They meticulously...

Shai-Hulud npm worm architecture and JavaScript supply chain attack payload 0

Shai-Hulud npm Worm Compromises Supply Chain

The Initial JavaScript Breach A single installation of a routine JavaScript library could expose a company’s cloud infrastructure, repositories, and internal services to attackers. The Shai-Hulud npm worm infiltrated highly popular packages. Users download...