Popular NPM Package Hijacked to Publish Crypto-mining Malware

The U.S. Cybersecurity and Infrastructure Security Agency on Friday warned of crypto-mining malware embedded in "UAParser.js," a popular JavaScript NPM library with over 6 million weekly downloads, days after the NPM repository moved to remove three rogue packages that were found to mimic the same library. <!--adsense--> The supply-chain attack targeting the open-source library saw three

from The Hacker News https://ift.tt/3Gbx01z
via IFTTT

Comments

Popular posts from this blog

Experts Reveal Over 150 Ways to Steal Control of 58 Android Stalkerware Apps

Critical Bugs Reported in Popular Open Source PJSIP SIP and Media Stack