May 6, 2022, 10:11 a.m. | Ax Sharma

Security Boulevard securityboulevard.com




On any given day, Sonatype's security research team analyzes dozens to hundreds of suspicious packages published to open source registries including npm and PyPI.


The post npm package downloads another package while exfiltrating your IP address and username appeared first on Security Boulevard.

address dependency confusion devzone downloads featured ip ip address malware prevention nexus firewall npm npm package package username vulnerabilities

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)