npm security
Malicious Packages in npm, PyPI Highlight Supply Chain Threat
Jeffrey Burt | | cyberattacks, npm security, PyPI, PyPI malicious packages, software supply chain attack, supply chain
Software developers are being targeted with malicious packages in npm and PyPI as threat groups launch software supply-chain attacks ...
Security Boulevard
Open-source repository malware sows Havoc
As part of the ReversingLabs research team's ongoing surveillance of open source repositories, we have identified aabquerys, a malicious npm package that downloads second and third stage malware payloads to systems that ...
Threat analysis: Malicious npm package mimics Material Tailwind CSS tool
ReversingLabs has discovered a malicious npm package disguised as the software tool Material Tailwind. Here's an in-depth look at our discovery — and threat analysis ...
OpenSSF’s npm best practices: A solid first step for software supply chain security — but trust issues remain
Here's what you need to know about the new OpenSSF npm security best practices ...

