New npm Supply Chain Attack Began with the Keyv Library Compromised Hundreds of Popular Packages

A new npm supply chain attack has turned trusted software packages into a route for credential theft. The campaign began after attackers compromised the maintainer account behind the widely used Keyv library, then used that access to push malicious releases across a growing number of projects. The incident matters because npm packages are routinely installed […]

This article has been indexed from Cyber Security News

Read the original article: