Researchers Find a Way Malicious NPM Libraries Can Evade Vulnerability Detection

Discussion in 'News Aggregator' started by The Hacker News, 3 Dec 2022.

  1. New findings from cybersecurity firm JFrog show that malware targeting the npm ecosystem can evade security checks by taking advantage of an "unexpected behavior" in the npm command line interface (CLI) tool. npm CLI's install and audit commands have built-in capabilities to check a package and all of its dependencies for known vulnerabilities, effectively acting as a warning mechanism for

    Continue reading...
     

Share This Page

Loading...