Conversation
Edited 1 month ago

Massive NPM Worm Attack

GitLab has discovered an NPM worm that is impacting a massive number of Git repositories and npm projects, ex-filtrating sensitive data such as cloud API keys and other security credentials.

According to Wiz, the scope of the attack is massive:

  • 27% of code and cloud environments
  • 700 npm packages
  • 25,000 git repositories
  • 500 GitHub users
  • 775 compromised GitHub access tokens
  • 373 AWS credentials
  • 300 GCP credentials
  • 115 Azure credentials

#npm #javascript #git

0
2
0

@tech-news It’s not your crazy uncle who will be ruining your Thanksgiving…

RE: https://akk.novalug.org/objects/dce3dc07-566c-41d9-9364-9d4a917a621a

0
0
0