Popular npm Project Used by Millions Hijacked in Supply-Chain Attack

Last week, Sonatype reported our discovery of three malicious npm cryptomining packages on npm: klow, klown, and okhsa. These packages, which infiltrated the npm registry between October 12th and 15th, installed Monero ...

Newly Found npm Malware Mines Cryptocurrency on Windows, Linux, macOS Devices

Sonatype’s automated malware detection system has caught multiple malicious packages on the npm registry this month. These packages disguise themselves as legitimate JavaScript libraries but were caught launching cryptominers on Windows, macOS ...

From Feature to Vulnerability: a spring-security-oauth2-client Story

Spring Security provides security services for the Spring IO Platform, available on their Github repository. Today we focus on the “oauth2” client, which provides an application with the capability to have users ...

This npm Package Could Have Brought Down Cloudflare’s Entire CDN and Millions of Websites

Cloudflare has patched a critical vulnerability in its open source content delivery network, CDNJS. The issue threatened the security, integrity, and availability of the wider supply chain ...

Sonatype Catches New PyPI Cryptomining Malware

Sonatype has identified malicious typosquatting packages infiltrating the PyPI repository that secretly pull in cryptominers on the affected machines ...

Open Source Attacks on the Rise: Top 8 Malicious Packages Found in npm

I get asked often what Sonatype's automated malware detection system, Release Integrity, has found so far. Great question! ...

Damaging Linux & Mac Malware Bundled within Browserify npm Brandjack Attempt

Over the weekend, Sonatype spotted a rather unique malware sample published to the npm registry, within a day of its release on npm ...

Deep Diving into CVE-2021-22114 Spring-integration-zip Path Traversal

Guess who's back? Earlier this month, CVE-2021-22114 in spring-integration-zip, returned for the second time to cause havoc ...

Netmask Flaw Leaves Millions Vulnerable While a PHP Git Server is Hacked in Software Supply Chain Attack

We’ve seeing so many software supply chain attacks in recent weeks that it’s hard for us to talk about all of them. But, in the last 24 hours, we’ve seen two major ...

PyPI and npm Flooded with over 5,000 Dependency Confusion Copycats

This week, a vigilante actor flooded PyPI and npm repositories with nearly 5,000 dependency confusion packages ...

Secure Guardrails