Supply chain attack hits npm package with 45,000 weekly downloads (www.bleepingcomputer.com)
from cm0002@lemmy.world to cybersecurity@infosec.pub on 09 May 16:51
https://lemmy.world/post/29384247

#cybersecurity

threaded - newest

qistoph@feddit.nl on 09 May 21:09 collapse

“obfuscated code hidden in the ‘dist/index.js’ file that was only visible when the user scrolled horizontally”

Malicious intentions aside, surely this is artistic ingenuity

Cyber@feddit.uk on 10 May 18:20 collapse

Wow.

I never knew wordwrap was a vulnerability scanner until now 🤭