Amazon Links NPM Supply-Chain Attacks
Amazon connected several high-profile NPM supply-chain attacks to North Korean hackers. The report also describes how malicious updates spread and why detection is getting harder.
Amazon connected several high-profile NPM supply-chain attacks to North Korean hackers. The report also describes how malicious updates spread and why detection is getting harder.
Supply chain attacks targeting npm and Python packages can expose development environments and organizational networks. Here are the key controls, actions, and prevention steps.
Researchers identified malicious npm packages that smuggled a cross-platform RAT into environments using Alibaba developer tools. The chain can persist, steal data, and move laterally.