New IronWorm malware hits 36 packages in npm supply-chain attack (www.bleepingcomputer.com)
from yogthos@lemmy.ml to security@lemmy.ml on 05 Jun 17:12
https://lemmy.ml/post/48335459

#security

threaded - newest

gary_host_laptop@lemmy.ml on 05 Jun 18:38 next collapse

is this like the second or third npm vulberability in a few months?

yogthos@lemmy.ml on 05 Jun 19:43 collapse

welcome to the wonderful world of npm

iByteABit@lemmy.ml on 05 Jun 20:14 collapse

Didn’t they add a new security measure just a week ago that now requires additional manual verification from the developer before a new version is distributed by npm?