← Front PageVulnerabilities Desk
Vulnerabilities
Supply chain attack on popular npm package affects 14M weekly downloads
npm supply chain attack hits 14M downloads/week — env vars exfiltrated via compromised maintainer account.
Summary written by editorial AI · Source link below
Maintainer account compromise leads to malicious code injection in a widely-used npm utility package, exfiltrating environment variables.
Continue at the source
Read the full report at GitHub AdvisoriesExternal link — opens at GitHub Advisories in a new tab.
§
Continue with
More from the Vulnerabilities Desk
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores2d
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code2d
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities3d
- Government Rails Site Hit Hours After CVE Patch3d
- Critical Citrix NetScaler auth bypass now leveraged in attacks3d