Infostealer campaign compromises 10 npm packages, targets devs
ID: 0d7549bc-6466-5035-a84e-5b9085eef7d8
STIX ID: report--0d7549bc-6466-5035-a84e-5b9085eef7d8
Feed Name: Bleeping Computer
Sonatype researchers discovered a supply-chain campaign in which ten npm packages—including the widely used country-currency-map—were updated with obfuscated scripts (/scripts/launch.js and /scripts/diagnostic-report.js) that steal environment variables and exfiltrate them to a pipedream.net endpoint; several compromised versions remain available on npm and the maintainer of country-currency-map deprecated the malicious release and recommended reverting to the prior safe version.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
