Npm package with millions of downloads is at risk from malware hijacking




  • A popular npm maintainer fell prey to a phishing attack, sharing login credentials with cybercriminals
  • The attackers accessed their npm account and pushed malware through a popular package
  • They were removed six hours later, but users should still take caution

Experts have warned that ‘is’, an npm package with more than 2.8 million weekly downloads, was also compromised in the same manner, and served malware for roughly six hours.

This comes shortly after Eslint-config-prettier, another popular npm package, was recently compromised in a supply chain attack which made it serve malware, after its maintainer, JounQin, received an email that spoofed the support@npmjs.com account, asking them to “verify” their account which, when they did, gave the attackers their login credentials.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *