Software Supply Chain Attacks: Regulation and Litigation Increase, as Barriers to Entry Drop tmcnet.com - get the latest breaking news, showbiz & celebrity photos, sport news & rumours, viral videos and top stories from tmcnet.com Daily Mail and Mail on Sunday newspapers.
ReversingLabs Mentioned in Gartner Software Supply Chain Security Report for Identifying Malware and Malicious Code – IT Business Net itbusinessnet.com - get the latest breaking news, showbiz & celebrity photos, sport news & rumours, viral videos and top stories from itbusinessnet.com Daily Mail and Mail on Sunday newspapers.
ReversingLabs researchers have identified a new, malicious supply chain attack affecting the npm platform. The “typosquatting” campaign first appeared in August and pushed a malicious package, node-hide-console-windows, which downloaded a Discord bot that facilitated the planting of an open source rootkit, r77. This is the first time ReversingLabs researchers have discovered a malicious open source package delivering rootkit functionality, and suggests that open source projects may increasingly be seen as an avenue by which to distribute malware.