B3NCLOUD ARTICLE INTELLIGENCE

ARTICLEVIEW

Zurück zu News

binding.gyp Supply Chain Attack Compromises Dozens of npm Packages Across Maintainer Accounts

A self-replicating worm has been quietly spreading across the npm registry using a method most security teams do not watch for. Instead of hiding inside package.json scripts, the attacker weaponized a tiny configuration file called binding.gyp to trigger malicious code the moment a developer runs...

Original-Artikel öffnen Zurück zur Übersicht