Malware has been deployed on 18 widely used developer utilities with over 2.6 billion weekly downloads as part of the largest npm supply chain attack so far, SiliconANGLE reports.Threat actors used a counterfeit npm support email and stolen credentials to infiltrate the libraries' maintainer account before compromising the packages' index.js files with illicit code that tracked multiple browser application programming interfaces and wallet interfaces to take over cryptocurrency transactions, according to an analysis from Aikido Security.Cybersecurity experts have emphasized the severity of the attack involving malware injections on the chalk, debug, and ansi-styles utilities, each of which has been downloaded at least 300 million times per week."The compromise of npm packages with over 2.6 billion weekly downloads highlights just how devastating upstream attacks can be when they exploit the foundational trust built into open-source ecosystems," said SOCRadar Cyber Intelligence Chief Information Security Officer Ensar Seker.
Supply chain, DevOps
Popular packages impacted by largest npm supply chain intrusion yet

(Credit: Araki Illustrations – stock.adobe.com)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds


