ChainDrop Malware Infects 1,300+ npm Packages in Supply-Chain Attack
The ChainDrop malware has compromised over 1,300 npm packages, impacting software supply chain security with billions of downloads monthly.
Tag
8 results in the archive.
The ChainDrop malware has compromised over 1,300 npm packages, impacting software supply chain security with billions of downloads monthly.
Adform's advertising scripts were compromised in a supply-chain attack that hijacks clipboard cryptocurrency addresses to redirect funds to attackers.
Amazon attributes multiple supply chain attacks on the Debug and Chalk npm packages to North Korean state-sponsored hackers, exposing risks to open-source software security.
The ShinyHunters extortion gang claimed responsibility for a data breach at Ernst & Young obtained through a supply-chain attack involving stolen system credentials.
An advanced threat actor exploits the update mechanism of ViPNet private networking software to attack Russian government agencies, illustrating ongoing espionage.
Seven malicious npm packages in the Vite ecosystem use a four-tier blockchain-based command-and-control infrastructure to deploy RAT malware, expanding the ChainVeil supply chain threat.
A malicious version of the Jscrambler npm package containing infostealer malware was published and downloaded nearly 1,500 times, posing risks to developers and users of this client-side security tool.
The jscrambler npm package version 8.14.0 was compromised to install a Rust-based infostealer via a preinstall hook, impacting Windows, macOS, and Linux environments.