all InfoSec news
npm package downloads another package while exfiltrating your IP address and username
May 6, 2022, 10:11 a.m. | Ax Sharma
Security Boulevard securityboulevard.com
On any given day, Sonatype's security research team analyzes dozens to hundreds of suspicious packages published to open source registries including npm and PyPI.
The post npm package downloads another package while exfiltrating your IP address and username appeared first on Security Boulevard.
address dependency confusion devzone downloads featured ip ip address malware prevention nexus firewall npm npm package package username vulnerabilities
More from securityboulevard.com / Security Boulevard
What is an IS (RBI) Audit?
1 day, 3 hours ago |
securityboulevard.com
Understanding Credential Phishing
1 day, 11 hours ago |
securityboulevard.com
Understanding Business Email Compromise (BEC)
1 day, 11 hours ago |
securityboulevard.com
Jobs in InfoSec / Cybersecurity
CyberSOC Technical Lead
@ Integrity360 | Sandyford, Dublin, Ireland
Cyber Security Strategy Consultant
@ Capco | New York City
Cyber Security Senior Consultant
@ Capco | Chicago, IL
Sr. Product Manager
@ MixMode | Remote, US
Security Compliance Strategist
@ Grab | Petaling Jaya, Malaysia
Cloud Security Architect, Lead
@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)