Malicious npm packages abuse dependency confusion to profile developer environments (opens in new tab)
A dependency confusion campaign leveraged 33 malicious npm packages to collect reconnaissance data from developer and build environments. This report details the attack chain, observed tradecraft, and detection opportunities to help organizations identify and disrupt related activity. The post appeared first on .
Read the original article