Tag: npm

Supply Chain Attacks Can Exploit Entry Points in Python, npm, and Open-Source Ecosystems
News

Supply Chain Attacks Can Exploit Entry Points in Python, npm, and Open-Source Ecosystems

Researchers studying cybersecurity have discovered that software supply chain assaults can be staged by abusing entry points in a variety of programming ecosystems, including PyPI, npm, Ruby Gems, NuGet, Dart Pub, and Rust Crates. There is a significant risk in the open-source community since attackers can use these entry points to launch malicious code when particular commands are executed, according to a paper released by Checkmarx researchers Yehuda Gelb and Elad Rapaport and shared with The Hacker News. Entry-point attacks provide threat actors with a more cunning and persistent way to compromise systems that can get past conventional security measures, according to the software supply chain security business read more about Supply Chain Attacks Can Exploit Entry Points in Pytho...
Trojanized jQuery Packages Found on npm, GitHub, and jsDelivr Code Repositories
News

Trojanized jQuery Packages Found on npm, GitHub, and jsDelivr Code Repositories

In an apparent example of a "complex and persistent" supply chain attack, trojanized versions of jQuery have been discovered being spread by unknown threat actors on npm, GitHub, and jsDelivr. Phylum stated in a report released last week that the substantial variability among packages makes this attack stand out. Using jQuery's rarely used 'end' function, which is internally invoked by the more widely used 'fadeTo' function from its animation utilities, the attacker has deftly concealed the malware. Up to 68 parcels have been connected to the initiative. From May 26 to June 23, 2024, they were added to the npm registry under a variety of names read more about Trojanized jQuery Packages Found on npm GitHub and jsDelivr Code Repositories. Get up to date on the latest cybersecuri...