Yet another NPM supply chain attack

Dex-chan lover
Joined
Jul 27, 2024
Messages
817
https://x.com/intcyberdigest/status/2062525624695083435

Or if you don't want to open twitter:
"‼️🚨 A new npm supply-chain attack compromised 57 packages across over 286 malicious versions in under 2 hours. The attackers used self-replicating malware, a new version of the Miasma worm, which also used evasion techniques to stay under the radar.

The payload targets CI/CD and developer credentials, including GitHub Actions secrets, cloud credentials, Vault tokens, SSH keys, npm and GitHub tokens, and password-manager stores. This variant also injects AI coding assistant config files at .claude, .cursor, .gemini, and .vscode paths, a separate persistence and repo-poisoning angle."

the fact that they have not yet enforced proper MFA for major pakcage maintainers convinces me theyre doign this shilt on puerpose
"no way to prevent this" says only package manager where this is a regular occurrence
rgar9l.png
 
Group Leader
Joined
Nov 9, 2024
Messages
57
The best thing one could ever do for security is trust arbitrary user input and remote resources with no verification done whatsoever. Just grab your favorite package manager and tell it "I want this thing, and I don't give a F what it ends up being." Best, ever. It's so easy and nice.
 

Users who are viewing this thread

Top