Over 800 npm Packages Found with Discrepancies, 18 Exploitable to 'Manifest Confusion'
ID: 102ad975-7bf8-558b-804e-5aa5dd4d464c
STIX ID: report--102ad975-7bf8-558b-804e-5aa5dd4d464c
Feed Name: The Hacker News
Threat Score
JFrog researchers identified over 800 npm packages with mismatches between the registry manifest and the package.json inside the tarball; 18 appear crafted to exploit a technique called "manifest confusion" that can hide malicious dependencies during installation, though most findings are proofs-of-concept and no active campaigns were observed—developers are advised to validate package contents and check for hidden dependencies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
