Software packages with more than 2 billion weekly downloads hit in supply-chain attack

D

Dan Goodin

Hackers planted malicious code in open source software packages with more than 2 billion weekly updates in what is likely to be the world’s biggest supply-chain attack ever.

The attack, which compromised nearly two dozen packages hosted on the npm repository, came to public notice on Monday in posts. Around the same time, Josh Junon, a maintainer or co-maintainer of the affected packages, he had been “pwned” after falling for an email that claimed his account on the platform would be closed unless he logged into a site and updated his two-factor authentication credentials.

Defeating 2FA the easy way​


“Sorry everyone, I should have paid more attention,” Junon, who uses the moniker Qix, wrote. “Not like me; have had a stressful week. Will work to get this cleaned up.”





 
RackNerd Leaderboard Banner

Back
Top