MikeTrendsTrends right now

search

NPM

Trends

  1. 1
    ChainDrop attack poisons npm packages via hijacked maintainer account●ChainDrop: attackers hijacked a maintainer's GitHub account and shipped poisoned npm releases with valid provenance. 400MmastodonTechnologySoftware320 h ago

    Security researchers are warning about a supply chain attack dubbed ChainDrop, in which attackers took over a package maintainer's GitHub account and published malicious npm releases carrying valid cryptographic provenance. The compromised releases reportedly touched around 400 packages with an estimated two billion weekly downloads. Commentators say the attack shows that provenance attestation works technically but cannot protect against a trusted account being compromised in the first place.

Repos