Tools

News

Notícias

Classificados

Cursos

Broker

IPv4:

IPv6:

 

UpOrDown
Ping
MTR
Smokeping
MTU Detect
Portscan
DNS
HTTP/SSL
My IP
IP Calc
IP Extractor
Uptime Monitor

Massive npm Attack Hits Billions of Weekly Downloads

Image © Arstechnica
Security researchers say the npm incident may be the largest supply-chain attack in history, affecting packages with billions of weekly downloads.

Hackers injected malicious code into npm packages with more than two billion weekly downloads, in what researchers say could be the largest open-source supply-chain attack to date.

The breach compromised nearly two dozen packages that are foundational to the JavaScript ecosystem and have thousands of downstream dependents.

The attackers breached the account of Josh Junon, a maintainer of several affected packages, after he was targeted by a phishing email that claimed his npm account would be closed unless he updated his two-factor authentication credentials.

Within about an hour of the compromise, those packages received updates that added code to siphon cryptocurrency funds, monitoring transactions and redirecting them to attacker-controlled wallets. The malicious addition ran to more than 280 lines of code and linked infected machines to attacker addresses.

Security researchers from Socket say the overlap with high-profile projects greatly expands the attack’s blast radius, and the incident appears to be a targeted attempt to maximize reach across the ecosystem. The npm team and researchers are coordinating incident response and remediation.

 

Arstechnica

Notícias relacionadas

Norte Conectado avança com testes de cabos de fibra
ABNT define vocabulário de gêmeos digitais
Semicondutores: vendas globais chegam a 1 trilhão em 2026
NGMN propõe simplificar redes 5G para reduzir custos
Roblox: Regulação de dados de crianças no Brasil
Oi atrai interessados em ativos de telefonia fixa

O ISP.Tools sobrevive graças aos anúncios.

Considere desativar seu bloqueador de anúncios.
Prometemos não ser intrusivos.

Consentimento para cookies

Utilizamos cookies para melhorar a sua experiência no nosso site.

Ao utilizar o nosso site, você concorda com o uso de cookies. Saiba mais