Hundreds of Malicious Packages Found in npm Registry

Security researchers discovered over 400 malicious packages in the popular open source registry npm in December, and dozens more in PyPI. Sonatype explained in a blog post that its AI tooling spotted 422 malicious npm packages focused mainly on data exfiltration via typosquatting or “dependency confusion attacks.” Additionally, it found 58 malicious packages in PyPI, including heavily obfuscated Discord token stealers.

Read full article on Infosecurity

 


Date:

Categorie(s):