Popular NPM Package Hijacked to Publish Crypto-mining Malware

Discussion in 'News Aggregator' started by Ravie Lakshmanan, 23 Oct 2021.

  1. The U.S. Cybersecurity and Infrastructure Security Agency on Friday warned of crypto-mining malware embedded in "UAParser.js," a popular JavaScript NPM library with over 6 million weekly downloads, days after the NPM repository moved to remove three rogue packages that were found to mimic the same library. <!--adsense--> The supply-chain attack targeting the open-source library saw three[​IMG]

    Continue reading...
     

Share This Page

Loading...