1,300 Malicious Packages Found in Popular npm JavaScript Package Manager

Malicious actors are using the npm registry as the start point for open source software (OSS) supply chain attacks.

Open source software offers huge potential for criminals and nation states to deliver widespread supply chain attacks. OSS registries provide a major feeding ground with easy access.

Read more atΒ Security Week

1,300 Malicious Packages Found in Popular npm JavaScript Package Manager - SECURITYWEEK

About Mend.io

Mend.io is built for every risk, across AI and AppSec. By securing the code layer and the AI layerβ€”and the interactions between them, where modern application risk now livesβ€”Mend.io extends proven AppSec workflows to the models, prompts, and agents inside today’s applications, delivering continuous protection across the entire AI application lifecycle.