npm Archives - Developer Tech News https://www.developer-tech.com/news/tag/npm/ Gaming, Apps, HTML5, Java, PHP, C#, .net, IOT Fri, 21 Jul 2023 12:24:47 +0000 en-GB hourly 1 https://www.developer-tech.com/wp-content/uploads/sites/3/2020/09/dev-icon-60x60.png npm Archives - Developer Tech News https://www.developer-tech.com/news/tag/npm/ 32 32 Checkmarx uncovers supply chain attacks targeting banking https://www.developer-tech.com/news/2023/jul/21/checkmarx-uncovers-supply-chain-attacks-targeting-banking/ https://www.developer-tech.com/news/2023/jul/21/checkmarx-uncovers-supply-chain-attacks-targeting-banking/#respond Fri, 21 Jul 2023 12:24:45 +0000 https://www.developer-tech.com/?p=44926 Checkmarx has uncovered a new and sophisticated cyber threat targeting the banking sector. The security testing firm’s research team detected two distinct open-source software supply chain attacks targeting financial institutions. These attacks, which involved advanced techniques and deceptive tactics, have raised alarm bells among cybersecurity experts. Attack one: NPM The first attack occurred on April... Read more »

The post Checkmarx uncovers supply chain attacks targeting banking appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2023/jul/21/checkmarx-uncovers-supply-chain-attacks-targeting-banking/feed/ 0
Sonatype uncovers further malicious PyPI and npm packages https://www.developer-tech.com/news/2023/jun/23/sonatype-uncovers-further-malicious-pypi-npm-packages/ https://www.developer-tech.com/news/2023/jun/23/sonatype-uncovers-further-malicious-pypi-npm-packages/#respond Fri, 23 Jun 2023 15:47:27 +0000 https://www.developer-tech.com/?p=44763 Sonatype continues to uncover a significant number of malicious packages within the PyPI and npm software registries. Among the flagged packages were several Python packages published on PyPI, masquerading as legitimate libraries named after the popular npm “colors” library. The malicious packages, including names such as “broke-rcl,” “brokescolors,” and “trexcolors,” exclusively targeted the Windows operating... Read more »

The post Sonatype uncovers further malicious PyPI and npm packages appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2023/jun/23/sonatype-uncovers-further-malicious-pypi-npm-packages/feed/ 0
Malware campaign targets official Python and JavaScript repos https://www.developer-tech.com/news/2022/dec/13/malware-campaign-targets-official-python-javascript-repos/ https://www.developer-tech.com/news/2022/dec/13/malware-campaign-targets-official-python-javascript-repos/#respond Tue, 13 Dec 2022 16:38:38 +0000 https://www.developer-tech.com/?p=44138 An active malware campaign is targeting official Python and JavaScript repositories. Software supply chain security firm Phylum spotted the campaign. Phylum said that it discovered the campaign after noticing a flurry of activity around typosquats of the popular Python requests package. Typosquats take advantage of simple typos to install malicious packages. In this case, the... Read more »

The post Malware campaign targets official Python and JavaScript repos appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2022/dec/13/malware-campaign-targets-official-python-javascript-repos/feed/ 0
GitHub notifies victims of OAuth token theft https://www.developer-tech.com/news/2022/apr/19/github-notifies-victims-of-oauth-token-theft/ https://www.developer-tech.com/news/2022/apr/19/github-notifies-victims-of-oauth-token-theft/#respond Tue, 19 Apr 2022 16:06:33 +0000 https://developer-tech.com/?p=43008 GitHub is notifying known victims of an ongoing attack using stolen third-party OAuth user tokens. OAuth user tokens maintained by Heroku and Travis CI were stolen and abused by an unauthorised party to download data from dozens of organisations, including npm. Mike Hanley, Chief Security Officer at GitHub, wrote in a blog post: “We have... Read more »

The post GitHub notifies victims of OAuth token theft appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2022/apr/19/github-notifies-victims-of-oauth-token-theft/feed/ 0
Large-scale supply chain attack used 218 malicious NPM packages https://www.developer-tech.com/news/2022/mar/24/large-scale-supply-chain-attack-used-218-malicious-npm-packages/ https://www.developer-tech.com/news/2022/mar/24/large-scale-supply-chain-attack-used-218-malicious-npm-packages/#respond Thu, 24 Mar 2022 14:32:40 +0000 https://developer-tech.com/?p=42774 A large-scale supply chain attack has been uncovered that used 218 malicious NPM packages. Researchers from JFrog claim that several of their automated analysers started throwing up alerts regarding a set of packages in the npm registry earlier this week. Over a few days, the number of packages swelled from around 50 packages to more... Read more »

The post Large-scale supply chain attack used 218 malicious NPM packages appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2022/mar/24/large-scale-supply-chain-attack-used-218-malicious-npm-packages/feed/ 0