ended4월 8일· 1 sources

@fairwords npm packages compromised by a self-propagating credential worm - steals tokens, infects other packages you own, then crosses to PyPI

Why it matters

<!-- SC_OFF --><div class="md"><p>Three @<code>fairwords</code> scoped npm packages were hit today by what appears to be the<br /> TeamPCP/CanisterWorm campaign. The interesting part isn't just the cr...

1
Sources
+0
24h
Growth
155d
Active

Sources

Related Issues