#npm
65 posts · Last used 20d
That's why you should migrate to #NPM v12, it prevents exactly this kind of attack: https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack
Every package in the family received two new files, setup.mjs and Math_Symbol.js, along with a "preinstall": "node setup.mjs" entry added to each package.json. Anyone who ran npm install against an affected version would have had setup.mjs execute automatically before their install completed.
Hey, hey, it's been a long time since the last huge supply chain attack (what about AUR? it's for nerds). NPM Supply Chain Attack returned again, this time infecting more than 444 packages with accumulation of 2B (yeah B for billion) downloads. The malware used is Shai-hulud again, but this time, the culprit is Copycat of TeamPCP.
What should you do?
- Check if you are affected, if so, downgrade your library version
- Rotate your keys and do 2FA
- Search for infected accounts in your system, if there is one, remove it... or kill it with cold blood.
More details: https://www.ox.security/blog/a-new-infostealer-worm-hits-npm-affecting-keyv-and-cacheable/
#cybersecurity #infosec #security #supplychainsecurity #supplychain #npm#shaihuludmalware







