Article 714AA Invisible npm malware pulls a disappearing act – then nicks your tokens

Invisible npm malware pulls a disappearing act – then nicks your tokens

by
from www.theregister.com - Articles on (#714AA)
Story ImagePhantomRaven slipped over a hundred credential-stealing packages into npm

A new supply chain attack dubbed PhantomRaven has flooded the npm registry with malicious packages that steal credentials, tokens, and secrets during installation. The packages appear safe when first downloaded, making them particularly difficult for security apps to identify....

External Content
Source RSS or Atom Feed
Feed Location http://www.theregister.co.uk/headlines.atom
Feed Title www.theregister.com - Articles
Feed Link https://www.theregister.com/
Reply 0 comments