An unknown threat actor is leveraging malicious npm packages to target developers with an aim to steal source code and configuration files from victim machines, a sign of how threats lurk consistently in open-source repositories.
“The threat actor behind this campaign has been linked to malicious activity dating back to 2021,” software supply chain security firm Checkmarx said in a report sharedRead More

Malicious npm Packages Aim to Target Developers for Source Code Theft [email protected] (The Hacker News)
by
Tags:
