Massive npm Supply Chain Attack: Over 2 Billion Downloads Affected
Aikido Security reported a significant supply chain attack on npm, involving the compromise of 18 widely used packages, including chalk
and debug
. These packages collectively amass over 2 billion downloads per week. The malicious updates embedded code that executed on client websites, potentially leading to data theft or unauthorized actions. The attack was identified through Aikido's intel feed, highlighting the vulnerabilities in the npm ecosystem and the importance of vigilant monitoring.
https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised
Comments
Post a Comment