The Hacker News - Node.js Users Beware: Manifest Confusion Attack Opens Door to Malware

The npm registry for the Node.js JavaScript runtime environment is susceptible to what's called a manifest confusion attack that could potentially allow threat actors to conceal malware in project dependencies or perform arbitrary script execution during installation. "A npm package's manifest is published independently from its tarball," Darcy Clarke, a former GitHub and npm engineering manager

from The Hacker News https://thehackernews.com/2023/07/nodejs-users-beware-manifest-confusion.html

Comments

Popular posts from this blog

US-CERT - AR18-352A: Quasar Open-Source Remote Administration Tool

KnowBe4 - Scam Of The Week: "When Users Add Their Names to a Wall of Shame"