New Supply Chain Malware Operation Hits npm and PyPI Ecosystems, Targeting Millions Globally

New Supply Chain Malware Operation Hits npm and PyPI Ecosystems, Targeting Millions Globally

Technology

New Supply Chain Malware Operation Hits npm and PyPI Ecosystems, Targeting Millions Globally
Cybersecurity researchers have flagged a supply chain attack targeting over a dozen packages associated with GlueStack to deliver malware.
The malware, introduced via a change to “lib/commonjs/index.js,” allows an attacker to run shell commands, take screenshots, and upload files to infected machines, Aikido Security told The Hacker News, stating these packages collectively account for nearly 1

Read original source here.

Products You May Like

Articles You May Like

Why it’s getting even harder to get into airport lounges now
Trump CFPB cuts reviewed by Fed inspector general
Book Riot’s Deals of the Day for June 8, 2025
New TokenBreak Attack Bypasses AI Moderation with Single-Character Text Changes
Oliver Anthony Announces Show At Joe Rogan’s Austin Comedy Club: “Their First Music Show Ever”