Menu

Post image 1
Post image 2
Post image 3
Post image 4
1 / 4
0

The never-ending supply chain attacks worm into SAP npm packages, other dev tools

go.theregister.com·Jessica Lyons·5 months ago
#DWm31UvM
Reading 0:00
15s threshold

The wave of supply chain attacks aimed at security and developer tools has washed up more victims, namely SAP and Intercom npm packages, plus the lightning PyPI package. The newly compromised packages as of Thursday include [email protected] (according to Google-owned Wiz) and [email protected] (says supply-chain security firm Socket) and [email protected] and 2.6.3. Attackers infected all versions with the same credential-stealing malware that, on Wednesday, poisoned multiple npm packages associated with SAP's JavaScript and cloud application development ecosystem. The SAP-related compromise is a Shai-Hulud-worm style campaign that calls itself Mini Shai-Hulud. So far, these SAP-related npm packages include: [email protected] @cap-js/[email protected] @cap-js/[email protected] @cap-js/[email protected] Collectively, these four packages receive about 572,000 weekly downloads and are widely used by developers building cloud applications.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More