Hacker news

Hackers Breach Toptal GitHub, Publish 10 Malicious npm Packages With 5,000 Downloads


In what’s the latest instance of a software supply chain attack, unknown threat actors managed to compromise Toptal’s GitHub organization account and leveraged that access to publish 10 malicious packages to the npm registry.
The packages contained code to exfiltrate GitHub authentication tokens and destroy victim systems, Socket said in a report published last week. In addition, 73 repositories

Source link

Podcast Cover
Loading latest episode…
0 0 votes
Article Rating
Subscribe
Notify of
Favatar
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments