NPM ecosystem at risk from “Manifest Confusion” attacks

The NPM (Node Package Manager) registry suffers from a security lapse called “manifest confusion,” which undermines the trustworthiness of packages and makes it possible for attackers to hide malware in dependencies or perform malicious script execution during installation. […]

Source: ​BleepingComputer  |  Read More 

Leave a Reply

Your email address will not be published. Required fields are marked *