Sonatype Discovers Two Malicious npm Packages

Sonatype Discovers Two Malicious npm Packages

Sonatype Security Research has identified a potential compromise of a trusted npm maintainer account that has now published two malicious npm packages — sbx-mask and touch-adv — designed to exfiltrate secrets from ...
npm Chalk and Debug Packages Hit in Software Supply Chain Attack

npm Chalk and Debug Packages Hit in Software Supply Chain Attack

The recent compromise of widely used npm packages chalk, debug, and more than a dozen others reveals that even the most trusted open source projects are not immune to compromise ...