NPM packages have been compromised by a self-replicating worm known as Shai-Hulud: https://www.blackduck.com/blog/npm-m...ud-threat.html
Basically it gets credentials and then publishes infected packages as the authenticated (compromised) user.
|
Results 1 to 4 of 4
Thread: NPM CompromisedThreaded View
|
Click Here to Expand Forum to Full Width |