all InfoSec news
npm package downloads another package while exfiltrating your IP address and username
May 6, 2022, 10:11 a.m. | Ax Sharma
Security Boulevard securityboulevard.com
On any given day, Sonatype's security research team analyzes dozens to hundreds of suspicious packages published to open source registries including npm and PyPI.
The post npm package downloads another package while exfiltrating your IP address and username appeared first on Security Boulevard.
address dependency confusion devzone downloads featured ip ip address malware prevention nexus firewall npm npm package package username vulnerabilities
More from securityboulevard.com / Security Boulevard
Jobs in InfoSec / Cybersecurity
SOC 2 Manager, Audit and Certification
@ Deloitte | US and CA Multiple Locations
Information Security Engineers
@ D. E. Shaw Research | New York City
Security Officer Level 1 (L1)
@ NTT DATA | Virginia, United States of America
Alternance - Analyste VOC - Cybersécurité - Île-De-France
@ Sopra Steria | Courbevoie, France
Senior Security Researcher, SIEM
@ Huntress | Remote US or Remote CAN
Cyber Security Engineer Lead
@ ASSYSTEM | Bridgwater, United Kingdom