URL has been copied successfully!
Malicious node-ipc npm Packages Trigger New Supply Chain Security Alarm
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Malicious node-ipc npm Packages Trigger New Supply Chain Security Alarm

A fresh supply chain attack targeting the widely used node-ipc npm package has raised new concerns across the JavaScript ecosystem after researchers uncovered multiple malicious releases containing an obfuscated credential stealer and backdoor functionality. Security analysts confirmed that several recently published package tarballs were infected with malware capable of harvesting sensitive data from developer systems and CI environments.

First seen on thecyberexpress.com

Jump to article: thecyberexpress.com/node-ipc-npm-package-credential-stealer/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link