ended4월 8일· 1 sources
@fairwords npm packages compromised by a self-propagating credential worm - steals tokens, infects other packages you own, then crosses to PyPI
Why it matters
<!-- SC_OFF --><div class="md"><p>Three @<code>fairwords</code> scoped npm packages were hit today by what appears to be the<br /> TeamPCP/CanisterWorm campaign. The interesting part isn't just the cr...
1
Sources
+0
24h
—
Growth
155d
Active