npm Archives - Developer Tech News https://www.developer-tech.com/news/tag/npm/ Gaming, Apps, HTML5, Java, PHP, C#, .net, IOT Mon, 04 Nov 2024 15:26:39 +0000 en-GB hourly 1 https://www.developer-tech.com/wp-content/uploads/2020/09/dev-icon-60x60.png npm Archives - Developer Tech News https://www.developer-tech.com/news/tag/npm/ 32 32 NPM supply chain attack uses Ethereum blockchain https://www.developer-tech.com/news/npm-supply-chain-attack-ethereum-blockchain/ https://www.developer-tech.com/news/npm-supply-chain-attack-ethereum-blockchain/#respond Mon, 04 Nov 2024 15:26:36 +0000 https://www.developer-tech.com/?p=46773 Checkmarx researchers have detected a unique supply chain attack within the NPM ecosystem that uses the Ethereum blockchain. The malicious package, dubbed “jest-fet-mock,” targets developers with a multi-platform malware employing Ethereum smart contracts for command-and-control (C2) operations. This marks a convergence of blockchain technology with traditional attack vectors—a method not yet observed in NPM packages. ... Read more »

The post NPM supply chain attack uses Ethereum blockchain appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/npm-supply-chain-attack-ethereum-blockchain/feed/ 0
Entry points threaten multiple open-source ecosystems https://www.developer-tech.com/news/entry-points-threaten-multiple-open-source-ecosystems/ https://www.developer-tech.com/news/entry-points-threaten-multiple-open-source-ecosystems/#respond Mon, 14 Oct 2024 13:58:48 +0000 https://www.developer-tech.com/?p=46680 While current tools have improved at detecting common tactics for exploiting open-source packages, a feature remains largely overlooked: entry points. Security researchers at Checkmarx uncovered how attackers can leverage entry points across multiple programming ecosystems, with a particular focus on PyPI, to trick victims into running malicious code. This method – while not allowing for... Read more »

The post Entry points threaten multiple open-source ecosystems appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/entry-points-threaten-multiple-open-source-ecosystems/feed/ 0
Roblox developers targeted by year-long malware campaign https://www.developer-tech.com/news/roblox-developers-targeted-year-long-malware-campaign/ https://www.developer-tech.com/news/roblox-developers-targeted-year-long-malware-campaign/#respond Mon, 02 Sep 2024 15:38:19 +0000 https://www.developer-tech.com/?p=46479 A sustained malware campaign targeting Roblox developers through malicious npm packages has been uncovered by Checkmarx security researchers. The attackers are impersonating the popular “noblox.js” library, publishing dozens of packages designed to steal sensitive information and compromise systems. The campaign, which has been active for over a year, exploits trust in the open-source ecosystem. It... Read more »

The post Roblox developers targeted by year-long malware campaign appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/roblox-developers-targeted-year-long-malware-campaign/feed/ 0
North Korean hackers target developers in latest npm attack wave https://www.developer-tech.com/news/north-korean-hackers-target-developers-npm-attack-wave/ https://www.developer-tech.com/news/north-korean-hackers-target-developers-npm-attack-wave/#respond Thu, 29 Aug 2024 12:16:20 +0000 https://www.developer-tech.com/?p=46462 A fresh offensive by suspected North Korean hacking groups has targeted the open-source software community with a series of malicious packages uploaded to the npm repository. Identified by cybersecurity firm Phylum, the attacks leverage multiple techniques and appear designed to steal cryptocurrency and sensitive data from unsuspecting developers. The campaign began on 12th August and... Read more »

The post North Korean hackers target developers in latest npm attack wave appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/north-korean-hackers-target-developers-npm-attack-wave/feed/ 0
Images weaponised in latest supply chain attack https://www.developer-tech.com/news/images-weaponised-latest-supply-chain-attack/ https://www.developer-tech.com/news/images-weaponised-latest-supply-chain-attack/#respond Tue, 16 Jul 2024 15:23:38 +0000 https://www.developer-tech.com/?p=46262 A series of malicious packages disguised as legitimate software have been discovered in the npm registry by cybersecurity firm Phylum. The packages – identified on 13 July 2024 – contained hidden command and control functionality embedded within image files, executed during the installation process. Phylum researchers uncovered two packages in this campaign, with one named... Read more »

The post Images weaponised in latest supply chain attack appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/images-weaponised-latest-supply-chain-attack/feed/ 0
Checkmarx uncovers supply chain attacks targeting banking https://www.developer-tech.com/news/checkmarx-uncovers-supply-chain-attacks-targeting-banking/ https://www.developer-tech.com/news/checkmarx-uncovers-supply-chain-attacks-targeting-banking/#respond Fri, 21 Jul 2023 12:24:45 +0000 http://www.developer-tech.com//?p=44926 Checkmarx has uncovered a new and sophisticated cyber threat targeting the banking sector. The security testing firm’s research team detected two distinct open-source software supply chain attacks targeting financial institutions. These attacks, which involved advanced techniques and deceptive tactics, have raised alarm bells among cybersecurity experts. Attack one: NPM The first attack occurred on April... Read more »

The post Checkmarx uncovers supply chain attacks targeting banking appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/checkmarx-uncovers-supply-chain-attacks-targeting-banking/feed/ 0
Sonatype uncovers further malicious PyPI and npm packages https://www.developer-tech.com/news/sonatype-uncovers-further-malicious-pypi-npm-packages/ https://www.developer-tech.com/news/sonatype-uncovers-further-malicious-pypi-npm-packages/#respond Fri, 23 Jun 2023 15:47:27 +0000 http://www.developer-tech.com//?p=44763 Sonatype continues to uncover a significant number of malicious packages within the PyPI and npm software registries. Among the flagged packages were several Python packages published on PyPI, masquerading as legitimate libraries named after the popular npm “colors” library. The malicious packages, including names such as “broke-rcl,” “brokescolors,” and “trexcolors,” exclusively targeted the Windows operating... Read more »

The post Sonatype uncovers further malicious PyPI and npm packages appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/sonatype-uncovers-further-malicious-pypi-npm-packages/feed/ 0
Malware campaign targets official Python and JavaScript repos https://www.developer-tech.com/news/malware-campaign-targets-official-python-javascript-repos/ https://www.developer-tech.com/news/malware-campaign-targets-official-python-javascript-repos/#respond Tue, 13 Dec 2022 16:38:38 +0000 http://www.developer-tech.com//?p=44138 An active malware campaign is targeting official Python and JavaScript repositories. Software supply chain security firm Phylum spotted the campaign. Phylum said that it discovered the campaign after noticing a flurry of activity around typosquats of the popular Python requests package. Typosquats take advantage of simple typos to install malicious packages. In this case, the... Read more »

The post Malware campaign targets official Python and JavaScript repos appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/malware-campaign-targets-official-python-javascript-repos/feed/ 0
GitHub notifies victims of OAuth token theft https://www.developer-tech.com/news/github-notifies-victims-of-oauth-token-theft/ https://www.developer-tech.com/news/github-notifies-victims-of-oauth-token-theft/#respond Tue, 19 Apr 2022 16:06:33 +0000 http://www.developer-tech.com//?p=43008 GitHub is notifying known victims of an ongoing attack using stolen third-party OAuth user tokens. OAuth user tokens maintained by Heroku and Travis CI were stolen and abused by an unauthorised party to download data from dozens of organisations, including npm. Mike Hanley, Chief Security Officer at GitHub, wrote in a blog post: “We have... Read more »

The post GitHub notifies victims of OAuth token theft appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/github-notifies-victims-of-oauth-token-theft/feed/ 0
Large-scale supply chain attack used 218 malicious NPM packages https://www.developer-tech.com/news/large-scale-supply-chain-attack-used-218-malicious-npm-packages/ https://www.developer-tech.com/news/large-scale-supply-chain-attack-used-218-malicious-npm-packages/#respond Thu, 24 Mar 2022 14:32:40 +0000 http://www.developer-tech.com//?p=42774 A large-scale supply chain attack has been uncovered that used 218 malicious NPM packages. Researchers from JFrog claim that several of their automated analysers started throwing up alerts regarding a set of packages in the npm registry earlier this week. Over a few days, the number of packages swelled from around 50 packages to more... Read more »

The post Large-scale supply chain attack used 218 malicious NPM packages appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/large-scale-supply-chain-attack-used-218-malicious-npm-packages/feed/ 0