Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

New compromised packages identified in largest npm attack in history

Summary

Follow-up on the largest npm attack in history: more compromised packages (duckdb, coveops/abi) surface as the phishing campaign's crypto-stealer spreads; only ~$500 stolen, and it is still active.
Published
Collected

original ↗

Related coverage

back