Article 6ZWVD Software packages with more than 2 billion weekly downloads hit in supply-chain attack

Software packages with more than 2 billion weekly downloads hit in supply-chain attack

by
Dan Goodin
from Ars Technica - All content on (#6ZWVD)

Hackers planted malicious code in open source software packages with more than 2 billion weekly updates in what is likely to be the world's biggest supply-chain attack ever.

The attack, which compromised nearly two dozen packages hosted on the npm repository, came to public notice on Monday in social media posts. Around the same time, Josh Junon, a maintainer or co-maintainer of the affected packages, said he had been pwned" after falling for an email that claimed his account on the platform would be closed unless he logged in to a site and updated his two-factor authentication credentials.

Defeating 2FA the easy way

Sorry everyone, I should have paid more attention," Junon, who uses the moniker Qix, wrote. Not like me; have had a stressful week. Will work to get this cleaned up."

Read full article

Comments

External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments