A malicious npm package reached over 2 million weekly downloads by hiding its payload in a routine library function rather than an install script.
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by ...
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices ...
A new npm supply chain campaign is hiding malware inside ordinary JavaScript package code instead of using the usual ...
North Korean threat actors, tracked as WaterPlum (also known as Contagious Interview), have compromised at least 30,000 ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results