@SheHacksPurple@infosec.exchange
Post #2499399
2026-05-10 20:18 UTC
🚨 Emergency DevSec Station Drop
There's an active npm supply chain attack happening right now. Compromised packages are stealing SSH keys, AWS credentials, GitHub tokens, browser passwords, and crypto wallets on install. Then using your publish token to infect every package you maintain.
One command can protect you immediately: npm config set ignore-scripts true
1/2
Replies (1)
-
@SheHacksPurple@infosec.exchange 2026-05-10 20:18
Do it today, please. Tell your team. Watch the full 60 seconds. Video link: https://twp.ai/4hpg2D #AppSec #SupplyChainSecurity #DevSecOps #SecureCoding #npm 2/2