packages Archives - Developer Tech News https://www.developer-tech.com/news/tag/packages/ Gaming, Apps, HTML5, Java, PHP, C#, .net, IOT Mon, 04 Nov 2024 15:26:39 +0000 en-GB hourly 1 https://www.developer-tech.com/wp-content/uploads/2020/09/dev-icon-60x60.png packages Archives - Developer Tech News https://www.developer-tech.com/news/tag/packages/ 32 32 NPM supply chain attack uses Ethereum blockchain https://www.developer-tech.com/news/npm-supply-chain-attack-ethereum-blockchain/ https://www.developer-tech.com/news/npm-supply-chain-attack-ethereum-blockchain/#respond Mon, 04 Nov 2024 15:26:36 +0000 https://www.developer-tech.com/?p=46773 Checkmarx researchers have detected a unique supply chain attack within the NPM ecosystem that uses the Ethereum blockchain. The malicious package, dubbed “jest-fet-mock,” targets developers with a multi-platform malware employing Ethereum smart contracts for command-and-control (C2) operations. This marks a convergence of blockchain technology with traditional attack vectors—a method not yet observed in NPM packages. ... Read more »

The post NPM supply chain attack uses Ethereum blockchain appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/npm-supply-chain-attack-ethereum-blockchain/feed/ 0
Entry points threaten multiple open-source ecosystems https://www.developer-tech.com/news/entry-points-threaten-multiple-open-source-ecosystems/ https://www.developer-tech.com/news/entry-points-threaten-multiple-open-source-ecosystems/#respond Mon, 14 Oct 2024 13:58:48 +0000 https://www.developer-tech.com/?p=46680 While current tools have improved at detecting common tactics for exploiting open-source packages, a feature remains largely overlooked: entry points. Security researchers at Checkmarx uncovered how attackers can leverage entry points across multiple programming ecosystems, with a particular focus on PyPI, to trick victims into running malicious code. This method – while not allowing for... Read more »

The post Entry points threaten multiple open-source ecosystems appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/entry-points-threaten-multiple-open-source-ecosystems/feed/ 0
Checkmarx uncovers persistent Python package threat https://www.developer-tech.com/news/checkmarx-uncovers-persistent-python-package-threat/ https://www.developer-tech.com/news/checkmarx-uncovers-persistent-python-package-threat/#respond Thu, 16 Nov 2023 13:00:03 +0000 http://www.developer-tech.com//?p=45359 Checkmarx has uncovered a threat actor that has been quietly infiltrating the open-source ecosystem for nearly six months, planting malicious Python packages with a focus on deception and financial gain. The malicious actor employed a systematic approach, disguising their packages with names closely resembling popular legitimate Python packages. These decoy packages, camouflaged to blend in,... Read more »

The post Checkmarx uncovers persistent Python package threat appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/checkmarx-uncovers-persistent-python-package-threat/feed/ 0
Sonatype uncovers further malicious PyPI and npm packages https://www.developer-tech.com/news/sonatype-uncovers-further-malicious-pypi-npm-packages/ https://www.developer-tech.com/news/sonatype-uncovers-further-malicious-pypi-npm-packages/#respond Fri, 23 Jun 2023 15:47:27 +0000 http://www.developer-tech.com//?p=44763 Sonatype continues to uncover a significant number of malicious packages within the PyPI and npm software registries. Among the flagged packages were several Python packages published on PyPI, masquerading as legitimate libraries named after the popular npm “colors” library. The malicious packages, including names such as “broke-rcl,” “brokescolors,” and “trexcolors,” exclusively targeted the Windows operating... Read more »

The post Sonatype uncovers further malicious PyPI and npm packages appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/sonatype-uncovers-further-malicious-pypi-npm-packages/feed/ 0
Large-scale supply chain attack used 218 malicious NPM packages https://www.developer-tech.com/news/large-scale-supply-chain-attack-used-218-malicious-npm-packages/ https://www.developer-tech.com/news/large-scale-supply-chain-attack-used-218-malicious-npm-packages/#respond Thu, 24 Mar 2022 14:32:40 +0000 http://www.developer-tech.com//?p=42774 A large-scale supply chain attack has been uncovered that used 218 malicious NPM packages. Researchers from JFrog claim that several of their automated analysers started throwing up alerts regarding a set of packages in the npm registry earlier this week. Over a few days, the number of packages swelled from around 50 packages to more... Read more »

The post Large-scale supply chain attack used 218 malicious NPM packages appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/large-scale-supply-chain-attack-used-218-malicious-npm-packages/feed/ 0