MikeTrendsTrends right now

✉news TechnologySoftware first seen 3 h ago, last 59 min ago, peak #23

101 Malicious npm Packages Enroll Developers in WhatsApp Groups

Original: 101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

Security researchers have identified 101 malicious packages on the npm registry that secretly add developers' WhatsApp accounts to groups without their consent. The campaign targets software developers who install compromised dependencies, raising concerns about supply chain attacks spreading through the widely used JavaScript package ecosystem and unwanted contact via WhatsApp.

Why now: Newly disclosed supply chain attacks targeting npm are a serious concern for developers worldwide.

npmWhatsAppThe Hacker News

Open on news →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/392470