Source |
The Hacker News |
Identifiant |
8658322 |
Date de publication |
2025-03-26 17:30:00 (vue: 2025-03-26 13:08:30) |
Titre |
Le package NPM malveillant modifie la bibliothèque locale \\ 'Ethers \\' pour lancer des attaques de coquilles inversées Malicious npm Package Modifies Local \\'ethers\\' Library to Launch Reverse Shell Attacks |
Texte |
Les chercheurs en cybersécurité ont découvert deux packages malveillants sur le registre NPM qui sont conçus pour infecter un autre package installé localement, soulignant l'évolution continue des attaques de chaîne d'approvisionnement logicielles ciblant l'écosystème open-source.
Les forfaits en question sont Ethers-Provider2 et Ethers-Providerz, avec le premier téléchargement téléchargé à ce jour depuis sa publication
Cybersecurity researchers have discovered two malicious packages on the npm registry that are designed to infect another locally installed package, underscoring the continued evolution of software supply chain attacks targeting the open-source ecosystem.
The packages in question are ethers-provider2 and ethers-providerz, with the former downloaded 73 times to date since it was published on |
Notes |
★★★
|
Envoyé |
Oui |
Condensat |
another are attacks chain continued cybersecurity date designed discovered downloaded ecosystem ethers evolution former have infect installed launch library local locally malicious modifies npm open package packages provider2 providerz published question registry researchers reverse shell since software source supply targeting times two underscoring |
Tags |
|
Stories |
|
Move |
|