Open Menu
AllLocalCommunitiesAbout
lotide
AllLocalCommunitiesAbout
Login

Supply chain attack hits npm package with 45,000 weekly downloads

⁨14⁩ ⁨likes⁩

Submitted ⁨⁨3⁩ ⁨weeks⁩ ago⁩ by ⁨cm0002@lemmy.world⁩ to ⁨cybersecurity@infosec.pub⁩

https://www.bleepingcomputer.com/news/security/supply-chain-attack-hits-npm-package-with-45-000-weekly-downloads/

source

Comments

Sort:hotnewtop
  • qistoph@feddit.nl ⁨3⁩ ⁨weeks⁩ ago

    “obfuscated code hidden in the ‘dist/index.js’ file that was only visible when the user scrolled horizontally”

    Malicious intentions aside, surely this is artistic ingenuity

    source
    • Cyber@feddit.uk ⁨2⁩ ⁨weeks⁩ ago

      Wow.

      I never knew wordwrap was a vulnerability scanner until now 🤭

      source