Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Since we published our initial analysis of the axios compromise, a deep dive into its hidden blast radius, and a report on the maintainer confirming it was social engineering, maintainers across the Node.js ecosystem have come out of the woodwork to report that they were targeted by the same social engineering campaign. The accounts now span some of the most widely depended-upon packages in the npm registry and Node.js core itself, and together they confirm that axios was not a one-off target.…
Soutenez Socket en consultant la ressource originale
Lire l'article original