Simple supply chain attack compromises hundreds of websites and apps
Simple supply chain attack compromises hundreds of websites and apps Typosquatting technique tricked tens of thousands of developers When you purchase through links on our site, we may earn an affiliate commission.Here’s how it works. A simple NPM supply-chain attack has led to the compromise of thousands of websites and desktop apps, researchers have found. According to ReversingLabs, a threat actor known as IconBurst has created a number of malicious NPM modules capable of exfiltrating serialized form data, and given them names almost identical to other, legitimate modules....