GHAPPIER Supply Chain Attack Compromises 65 GitHub Repositories and Poisons npm Package

A newly uncovered software supply chain attack has shown how quickly a trusted developer account can become a delivery route for malware. The operation, tracked as GHAPPIER, reached 65 GitHub repositories, infecting 73 files across 22 accounts. It involved a legitimate npm package that distributed a malicious loader to users. Attackers used access to a […]

This article has been indexed from Cyber Security News

Read the original article: