New compromised packages identified in largest npm attack in history
jfrog.com | blog | #malware | #npm | #phishing | #jfrog | #supply-chain-attack | #cryptocurrency-stealer
Summary
Follow-up on the largest npm attack in history: more compromised packages (duckdb, coveops/abi) surface as the phishing campaign's crypto-stealer spreads; only ~$500 stolen, and it is still active.
- Published
- Collected
Skip to content