Source |
The Hacker News |
Identifiant |
3552575 |
Date de publication |
2021-10-23 02:23:13 (vue: 2021-10-23 10:05:51) |
Titre |
Popular NPM Package Hijacked to Publish Crypto-mining Malware |
Texte |
The U.S. Cybersecurity and Infrastructure Security Agency on Friday warned of crypto-mining malware embedded in "UAParser.js," a popular JavaScript NPM library with over 6 million weekly downloads, days after the NPM repository moved to get rid of three rogue packages that were found to mimic the same library.
The supply-chain attack targeting the open-source library saw three |
Notes |
|
Envoyé |
Oui |
Condensat |
after agency attack chain crypto cybersecurity days downloads embedded found friday warned of get hijacked infrastructure javascript library malware million mimic mining moved npm open over package packages popular publish repository rid rogue same saw security source supply targeting three uaparser weekly |
Tags |
Malware
|
Stories |
|
Move |
|