Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Still Trusting Automated Patches Blindly? Think Again

Summary

How a phishing breach of the eslint-config-prettier maintainer's npm account shipped six malicious versions and three more infected packages (~78M weekly downloads) with a Windows malware payload.
Published
Collected

original ↗

Related coverage

back