09 junho SeedSweep: Ten Crypto-Themed npm Packages That Only Run When No One Is Watching
Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident....
Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident....
Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident....
Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident....
Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident....
Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident....
Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident....
Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident....
Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident....
An npm dependency confusion attack used eight malicious packages to fingerprint hosts and send RCE telemetry to Telegram....
A npm typosquatting attack used six malicious EVM/DeFi packages to steal developer keys, wallets, secrets, and .env files....
O malware FauxCode Claude Code para npm usava pacotes CLI falsos para interceptar o tráfego da API por meio de ataques Man-in-the-Middle (MITM) com pacotes CA e sequestro de URL base.
O ataque de typosquatting do DevTap no npm usou seis pacotes maliciosos para espionar estações de trabalho de desenvolvedores e abusar da confiança do npm.