Microsoft discovers new npm attack in 14 packages (opens in new tab)
Microsoft has discovered a new supply chain attack in which an attacker published fourteen malicious npm packages within a few hours. The packages masqueraded as tools for OpenSearch, Elasticsearch, and other widely used development environments, but were actually designed to steal sensitive credentials from cloud and CI/CD platforms. According to ...
Read the original article