Still Trusting Automated Patches Blindly? Think Again
jfrog.com | blog | #supply-chain | #malware | #npm | #phishing | #patch-management | #eslint-config-prettier
Summary
How a phishing breach of the eslint-config-prettier maintainer's npm account shipped six malicious versions and three more infected packages (~78M weekly downloads) with a Windows malware payload.
- Published
- Collected
Skip to content