Diamond Member ThaHaka 0 Posted April 22 Diamond Member Share Posted April 22 This is the hidden content, please Sign In or Sign Up Cybersecurity researchers have flagged a fresh set of packages that have been compromised by bad actors to deliver a self-propagating worm that spreads through stolen developer npm tokens. The supply chain worm has been detected by both Socket and StepSecurity, with the companies tracking the activity under the name CanisterSprawl owing to the use of an ICP canister to exfiltrate the stolen data This is the hidden content, please Sign In or Sign Up 0 Quote Link to comment https://hopzone.eu/forums/topic/310136-h4ckn3wsself-propagating-supply-chain-worm-hijacks-npm-packages-to-steal-developer-tokens/ Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.