40-npm-packages-compromised-in-supply-chain-attack-using-bundle.js-to-steal-credentials

“`html

Cybersecurity analysts have identified a new software supply chain assault aimed at the npm registry that has impacted over 40 packages associated with various maintainers.

The breached versions incorporate a function (NpmModule.updatePackage) that retrieves a package tarball, alters package.json, embeds a local script (bundle.js), repackages the archive, and republishes it, facilitating

“`


Leave a Reply

Your email address will not be published. Required fields are marked *

Share This