NPM account takeovers via expired maintainer domains
You don't need to exploit npm to poison it. Buy the expired email domain behind a maintainer's account, reset the password, and the package is yours. We scanned 2.1 million packages, extracted 6.7 million maintainer emails, and found 675 expired domains leaving 2,843 packages open to takeover. Those packages sit under 257,000+ dependent repos and 93,000 downstream packages. One lapsed domain renewal, a supply chain full of blast radius.
https://laburity.com/research-npm-account-takeovers/
#SupplyChainSecurity #npm #AccountTakeover #AppSec #Laburity
You've seen all posts