Sonatype Discovers Two Malicious npm Packages

Sonatype Security Research has identified a potential compromise of a trusted npm maintainer account that has now published two malicious npm packages — sbx-mask and touch-adv — designed to exfiltrate secrets from victims’ computers.

The post Sonatype Discovers Two Malicious npm Packages appeared first on Security Boulevard.

This article has been indexed from Security Boulevard

Read the original article: