Minacce e avversari · Supply chain
Un package npm firmato può comunque essere una trappola se la pipeline CI/CD o l'account del maintainer sono compromessi. La rottura non è solo una dipendenza difettosa; il percorso di publishing trusted stesso può essere usato per distribuire veleno che continua a sembrare legittimo agli strumenti di verification.
13 fonti · 11 giu
The Register Security
Shai-Hulud malware worms Red Hat npm package versions downloaded 80K times a week
TeamPCP? Or copycat malware dev?
originaleThe Hacker News
IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks
Multiple npm supply chain attacks used 50+ poisoned packages to spread IronWorm, a Rust-based stealer, and a Miasma worm variant.
originaleDark Reading
Rust-Written IronWorm Hits NPM Supply Chain
Like Shai-Hulud, the campaign targets developers to steal credentials and reuses them to propagate across the software supply channel.
originalePart of the PlainSec briefing for 2026-05-30
Every edition of this story: Provenienza Valida non Dimostra più la Sicurezza del Package