The Changelog Podcast: Practical Steps to Stay Safe on npm
socket.dev·10h·
Discuss: Hacker News
Flag this post

Following one of the most intense periods of supply chain attacks in npm’s history, The Changelogpodcast invited Socket founder and CEO Feross Aboukhadijeh to unpack what happened and what developers can do to protect themselves.

While the headline-grabbing compromises of popular libraries and utilities have subsided, malicious packages continue to appear on npm every day. In our latest threat research, we uncovered ten typosquatted npm packages that used fake CAPTCHAs and system fingerprinting to deploy a cross-platform credential stealer.

“The faster you upgrade your packages, the more safe you are from software vulnerabiliti…

Similar Posts

Loading similar posts...