logo

Apache Cordova App Harness Targeted in Dependency Confusion Attack

ID: 5590f03f-99e9-524a-ad8d-9656b4aff6bb

STIX ID: report--5590f03f-99e9-524a-ad8d-9656b4aff6bb

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2024-04-23

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Security researchers discovered a dependency-confusion vulnerability in the archived Apache Cordova App Harness where an internal dependency was referenced without a relative path, enabling an attacker to publish a malicious npm package under the same name; the bogus package received over 100 downloads before Apache took ownership. The report underscores the supply-chain risks of abandoned open-source projects and recommends defensive measures such as using private registries, publishing placeholder packages, and treating third-party/archived dependencies as potential weak links.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.