all InfoSec news
npm package downloads another package while exfiltrating your IP address and username
May 6, 2022, 10:11 a.m. | Ax Sharma
Sonatype Blog blog.sonatype.com
On any given day, Sonatype's security research team analyzes dozens to hundreds of suspicious packages published to open source registries including npm and PyPI.
address dependency confusion devzone downloads featured ip ip address malware prevention nexus firewall npm npm package package username vulnerabilities
More from blog.sonatype.com / Sonatype Blog
The essential duo of SCA and SBOM management
6 days, 13 hours ago |
blog.sonatype.com
Automating and maintaining SBOMs
1 week, 6 days ago |
blog.sonatype.com
Cyber readiness and SBOMs
3 weeks, 2 days ago |
blog.sonatype.com
Open source ML/AI models: attackers' next target
3 weeks, 6 days ago |
blog.sonatype.com
Jobs in InfoSec / Cybersecurity
SOC 2 Manager, Audit and Certification
@ Deloitte | US and CA Multiple Locations
Information Security Engineers
@ D. E. Shaw Research | New York City
Cloud Security Engineer
@ Pacific Gas and Electric Company | Oakland, CA, US, 94612
Penetration Tester (Level 2)
@ Verve Group | Pune, Mahārāshtra, India
Senior Security Operations Engineer (Azure)
@ Jamf | US Remote
(Junior) Cyber Security Consultant IAM (m/w/d)
@ Atos | Berlin, DE, D-13353