Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Yogthos
Yogthos
@yogthos@social.marxist.network  ·  activity timestamp 3 weeks ago

A sophisticated, worm-like malware is spreading through npm packages. It steals GitHub, cloud, and npm credentials, then uses them to infect all packages maintained by a compromised developer and exfiltrate data.

The malware has a dead man's switch. If it loses access to its command servers, it triggers a destructive payload that attempts to delete user files on the infected system. Do not abruptly cut off infected machines.

https://about.gitlab.com/blog/gitlab-discovers-widespread-npm-supply-chain-attack

#security #npm #javascript #programming

  • Copy link
  • Flag this post
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.41 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct