Supply Chain Attack on npm, PyPI, and Crates Registries with 34 Malicious Packages (varutra.com)
0xBASE INTEL BRIEF
- 34 malicious packages discovered on npm, PyPI, and Crates
- Supply chain attack targets developer credentials
- Threatens digital autonomy via open-source dependencies
- No attribution provided
"Security researchers discovered 34 malicious packages across the npm, PyPI, and Crates package registries. The supply chain attack targets developer environments to steal credentials and sensitive data, threatening European digital autonomy by compromising widely used open-source dependencies."
#supply chain security
#open-source risk
#credential theft
no comments yet.