Another attack on the NPM Supply Chain has been detected. Tinycolor (with a weekly download count of 2.2 million) released a malicious version that runs an information-stealing program during the npm postinstall script execution to scan and steal sensitive data. This malicious payload abused legitimate sensitive information scanning tools.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 8
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin