Malicious Packages articles

Original research and analysis on malicious packages in open source registries β€” attack techniques like typosquatting, plus detection and defense.

CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive - Blog cover CanisterWorm

CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive

Deep dive into the self-spreading CanisterWorm.

Read More
CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive - blog post npm fake font packages

NPM User Flooding Registry with Fake Font Packages

Analysis of an npm account flooding the registry with malformed font packages.

Read More
CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive - Blog Zero day Shai hulud V2

Shai-Hulud: The Second Coming

See how the latest Shai-Hulud attack works.

Read More
CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive - Blog cover Mend Main Blues 1

NPM Ecosystem Under Siege: Self-Propagating Malware Compromises 187 Packages in a Huge Supply Chain Attack

A major NPM breach exposed 187 packages.

Read More
CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive - npm supply chain attack blog

NPM Supply Chain Attack: Sophisticated Multi-Chain Cryptocurrency Drainer Infiltrates Popular Packages

A sophisticated npm supply chain attack compromised popular packages

Read More
CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive - truffelvscode blog post

Fake VS Code Extension on npm Spreads Multi-Stage Malware

Learn about a fake VS-code extension on npmβ€”truffelvscodeβ€”typosquatting the popular truffle for VS-code extension.

Read More
CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive - CVE Critical race condition in Apache Tomcat blog

CVE-2024-50379: A Critical Race Condition in Apache Tomcat

An Apache Tomcat web server vulnerability has been published, exposing the platform to remote code execution through a race condition failure.

Read More
CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive - Solana Supply Chain Security Blog graphic

The @Solana/web3.js Incident: Another Wake-Up Call for Supply Chain Security

This post covers the attack flow, how it happened, and the importance of supply chain security.

Read More
CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive - polyfill supply chain attack post

More than 100K sites impacted by Polyfill supply chain attack

The new Chinese owner tampers with the code of cdn.polyfill.io to inject malware targeting mobile devices.

Read More
CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive - shrinking security debt with dependency management white paper

Critical Backdoor Found in XZ Utils (CVE-2024-3094) Enables SSH Compromise 1

Discover how CVE-2024-3094 affects XZ Utils and enables SSH compromise. Get insights on detection, mitigation, and system security.

Read More
CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive - blog 2 1

Over 100 Malicious Packages Target Popular ML PyPi Libraries

Discover the latest security threat as over 100 malicious packages target popular ML PyPi libraries. Learn about the attack methods.

Read More
CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive - eight considerations for thwarting malicious packages

8 Considerations for Thwarting Malicious Packages

Learn how to protect your code from malicious packages with these eight considerations. Stay ahead of supply chain security threats.

Read More
CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive - theres a new stealer variant in town and its using electron to stay fully undetected

There’s a New Stealer Variant in Town, and It’s Using Electron to Stay Fully Undetected

Discover the latest threat in town - a new info-stealer variant using Electron to remain undetected. Learn about its attack flow.

Read More
CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive - brandjacking

What Risks Do You Run from Brandjacking, and How Do You Overcome Them?

Learn about the risks of brandjacking & how to overcome them with application security tools & practices. Protect your org from cyber threats.

Read More
CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive - cybersecurity risks posed by typosquatting and how you can beat them

What Cybersecurity Risks Does Typosquatting Pose, and How Can You Beat Them?

Find out what typosquatting is, why it is such a threat, and what you can do to stop it.

Read More
CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive - understanding the anatomy of a malicious package attack

Understanding the Anatomy of a Malicious Package Attack

Learn to protect your applications from malicious packages with our guide. Understand the anatomy of attacks and how to prevent them.

Read More