Security researchers at Checkmarx Zero have identified a malware campaign that circumvents npm's recent crackdown on lifecycle scripts, one of the package manager's key defensive measures against supply chain attacks. npm (short for Node Package Manager) is the default package manager for the Node.js JavaScript runtime environment. It helps developers install, share, and manage reusable code libraries (called packages) in their projects. The discovery signals that attackers are adapting quickl
npmsecurity (2)
Many malware attacks against open-source software components have compromised thousands of software packages and repositories, but the practical damage these attacks have caused organizations is harder to quantify. The longer-term and indirect costs of these attacks may prove most significant for organizations. Open-source components and software have long been a well-established source of threat activity. The widespread use, combined with the broad variance in how well-supported different pro