NPM package ‘is’ with 2.8M weekly downloads infected devs with malware (www.bleepingcomputer.com)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 24 Jul 12:09
https://sh.itjust.works/post/42710921

#cybersecurity

threaded - newest

HubertManne@piefed.social on 24 Jul 14:56 next collapse

holy crap:

On July 19, 2025, the package's primary maintainer, John Harband, announced that versions 3.3.1 through 5.0.0 contained malware and were removed roughly 6 hours after threat actors submitted them to npm.

Cyber@feddit.uk on 24 Jul 15:48 collapse

So, is that just a ‘developer’ component, or have I got to analyse all my systems now for the NPM components in the article’s list?