Tim's Lemmy
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Kid@sh.itjust.worksM to Cybersecurity@sh.itjust.worksEnglish · 10 days ago

TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO

thehackernews.com

external-link
message-square
5
link
fedilink
41
external-link

TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO

thehackernews.com

Kid@sh.itjust.worksM to Cybersecurity@sh.itjust.worksEnglish · 10 days ago
message-square
5
link
fedilink
TrapDoor spread 34 malicious packages across npm, PyPI, and Crates.io, stealing developer credentials and enabling persistence.
alert-triangle
You must log in or # to comment.
  • cinoreus@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    9 days ago

    NPM is literally a malware at this point

    • PortNull@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      9
      ·
      9 days ago

    • Bluescluestoothpaste@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      2
      ·
      9 days ago

      Wait like for real? Im noob but i thought npm is like the standard package manager?

      • placebo@lemmy.zip
        link
        fedilink
        English
        arrow-up
        4
        ·
        8 days ago

        Wait like for real?

        No. But it’s a huge platform with a lot of users and no oversight whatsoever.

      • PumaStoleMyBluff@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        8 days ago

        While it’s not literally malware, it should be treated like a random upload host like mega.nz or whatever

Cybersecurity@sh.itjust.works

cybersecurity@sh.itjust.works

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

  • Be respectful. Everyone should feel welcome here.
  • No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
  • No Ads / Spamming.
  • No pornography.

Community Rules

  • Idk, keep it semi-professional?
  • Nothing illegal. We’re all ethical here.
  • Rules will be added/redefined as necessary.

If you ask someone to hack your “friends” socials you’re just going to get banned so don’t do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 15 users / day
  • 476 users / week
  • 1.71K users / month
  • 3.99K users / 6 months
  • 1 local subscriber
  • 10.1K subscribers
  • 4.57K Posts
  • 6.44K Comments
  • Modlog
  • mods:
  • Kid@sh.itjust.works
  • Lanky_Pomegranate530@midwest.social
  • UI: unknown version
  • BE: 0.19.18
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org