Malicious Packages articles

Original research and analysis on malicious packages in open source registries β€” attack techniques like typosquatting, plus detection and defense.

The Unseen Risks of Open Source Dependencies: The Case of an Abandoned Name - unseen risks of open source dependencies case of an abandoned name e1685538190274

The Unseen Risks of Open Source Dependencies: The Case of an Abandoned Name

Mend.io research discovered a threat actor takeover of the name β€˜gemnasium-gitlab-service', a retired Ruby gem with two million+ downloads.

Read More
The Unseen Risks of Open Source Dependencies: The Case of an Abandoned Name - what are malicious packages blog post

What are Malicious Packages? How Do They Work?

Learn about malicious packages and the growing threat they pose to software supply chains.

Read More
The Unseen Risks of Open Source Dependencies: The Case of an Abandoned Name - blog 2 1

Deceptive β€˜Vibranced’ npm Package Discovered Masquerading as Popular β€˜Colors’ Package

Discover the threat of the 'Vibranced' npm package masquerading as 'Colors'. Learn about its stages of execution, obfuscation techniques.

Read More
The Unseen Risks of Open Source Dependencies: The Case of an Abandoned Name - Yandex Data Leak Triggers Malicious Package Publication 1

Yandex Data Leak Triggers Malicious Package Publication

Discover how the Yandex data leak triggered malicious package publication, leading to supply chain security risks.

Read More
The Unseen Risks of Open Source Dependencies: The Case of an Abandoned Name - blog image

Malicious Code Deletes Directories If You Do Not Have a License

Discover how malicious code can delete directories if you don't have a license. Learn about supply chain security and license compliance.

Read More
The Unseen Risks of Open Source Dependencies: The Case of an Abandoned Name - blog RubyGems vulnerabilities

To use rest_client, or to use rest-client, that is the question

Discover the risks of using rest_client versus rest-client in RubyGems. Learn how a recent attack was thwarted.

Read More
The Unseen Risks of Open Source Dependencies: The Case of an Abandoned Name - npm Massive Dependency Confusion Attack

Cybercriminals targeted users of packages with a total of 1.5 billion weekly downloads on npm

Stay informed about the latest supply chain security incident targeting npm users. Learn about the malicious packages and more.

Read More
The Unseen Risks of Open Source Dependencies: The Case of an Abandoned Name - npm Massive Dependency Confusion Attack

Popular Cryptocurrency Exchange dYdX Has Had Its NPM Account Hacked

dYdX, a popular cryptocurrency exchange, had its NPM account hacked in a supply chain attack. Learn how to protect against similar attacks.

Read More
The Unseen Risks of Open Source Dependencies: The Case of an Abandoned Name - php 1

Typosquatting Malware Found in Composer Repository

Protect your PHP applications from typosquatting malware found in Composer Repository. Learn how attackers exploit vulnerabilities.

Read More
The Unseen Risks of Open Source Dependencies: The Case of an Abandoned Name - Todays Security Tidbit An Encrypted JSON File Containings Malicious Code

Today’s Security Tidbit: An Encrypted JSON File Containing Malicious Code

Discover how encrypted JSON files are being used to hide malicious code. Learn about the latest security findings and how to protect your apps.

Read More
The Unseen Risks of Open Source Dependencies: The Case of an Abandoned Name - How to Conquer Remote Code Execution RCE in npm

How to Conquer Remote Code Execution (RCE) in npm

Learn how to conquer Remote Code Execution (RCE) attacks in npm. Find out why npm is susceptible, the threats of RCE, and more.

Read More
The Unseen Risks of Open Source Dependencies: The Case of an Abandoned Name - npm Massive Dependency Confusion Attack

Single Author Uploaded 168 Packages to npm as Part of a Massive Dependency Confusion Attack

Discover how a single author uploaded 168 malicious npm packages in a dependency confusion attack. Learn how Mend blocked these threats.

Read More
The Unseen Risks of Open Source Dependencies: The Case of an Abandoned Name - Blog

New Typosquatting Attack on npm Package ’colors’ Using Cross language Technique Explained

Discover the latest typosquatting attack on the npm package 'colors' using a cross-language technique.

Read More
The Unseen Risks of Open Source Dependencies: The Case of an Abandoned Name - RubyGems Critical CVE 2022 29176

Impact Analysis: RubyGems Critical CVE-2022-29176 Unauthorized Package TakeoverΒ 

Impact Analysis of RubyGems Critical CVE-2022-29176 Unauthorized Package Takeover. Learn about the vulnerability, impact assessment, and more

Read More
The Unseen Risks of Open Source Dependencies: The Case of an Abandoned Name - news AWS target

AWS Targeted by a Package Backfill Attack

Discover how AWS was targeted by a malicious package backfill attack, the methods used by attackers, and how to protect against such attacks.

Read More
The Unseen Risks of Open Source Dependencies: The Case of an Abandoned Name - malicious package npm

A Malicious Package Found Stealing AWS AIM data on npm has Similarities To Capital One Hack

Discover how a malicious package found stealing AWS AIM data on npm has similarities to the Capital One hack. Learn about the threat.

Read More