NPM Flaws Let Attackers Target Packages for Account Takeover
ID: 6a5f3f18-69a3-5bae-872d-5055483b0f06
STIX ID: report--6a5f3f18-69a3-5bae-872d-5055483b0f06
Feed Name: Aqua Security Blog
Team Nautilus discovered and responsibly disclosed two npm information-disclosure flaws that allowed unauthenticated enumeration of maintainers' 2FA status and whether organizations enforced 2FA; using these findings and leaked-password data they measured supply-chain exposure and found substantial risk (32% of top-35 packages and 72% of devDependencies), demonstrating how compromised dependency maintainers could enable account takeovers and downstream malicious package updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
