Malware e strumenti · Supply chain
Il worm npm bypassa i controlli sugli script tramite i metadati di build La rottura è che il controllo dei package che cerca solo gli npm lifecycle scripts può essere ingannato. Miasma v2 fa eseguire codice durante l’installazione tramite un piccolo file binding.gyp malevolo, così un package può sembrare privo di script e comunque eseguire un worm.
3 fonti · 4 giu
Cronologia Fonti 4 giu Snyk Blog
Node-gyp Supply Chain Compromise | Snyk
A self-propagating npm worm uses binding.gyp and node-gyp to run code at install time, steal secrets, persist in GitHub, and spread through packages.
originale 4 giu Semgrep Blog
Miasma v2: Self-Spreading npm Worm Now Uses Malicious binding.gyp file and Compromises 57 Packages
But with a switch from install scripts to binding.gyp, this latest wave has swept up 57 packages across 286+ malicious versions.
originale 1 giu Wiz Research
Miasma: Supply Chain Attack Targeting RedHat npm Packages | Wiz Blog
Detect and mitigate malicious npm packages linked to the latest npm supply chain attack, based on the open sourced Mini Shai-Hulud malware.
originale Part of the PlainSec briefing for 2026-06-04
Every edition of this story: Il worm npm bypassa i controlli sugli script tramite i metadati di build
Altro da oggi
Malware e strumenti · Supply chain
Il worm npm bypassa i controlli sugli script tramite i metadati di build La rottura è che il controllo dei package che cerca solo gli npm lifecycle scripts può essere ingannato. Miasma v2 fa eseguire codice durante l’installazione tramite un piccolo file binding.gyp malevolo, così un package può sembrare privo di script e comunque eseguire un worm.
3 fonti · 4 giu
Cronologia Fonti 4 giu Snyk Blog
Node-gyp Supply Chain Compromise | Snyk
A self-propagating npm worm uses binding.gyp and node-gyp to run code at install time, steal secrets, persist in GitHub, and spread through packages.
originale 4 giu Semgrep Blog
Miasma v2: Self-Spreading npm Worm Now Uses Malicious binding.gyp file and Compromises 57 Packages
But with a switch from install scripts to binding.gyp, this latest wave has swept up 57 packages across 286+ malicious versions.
originale 1 giu Wiz Research
Miasma: Supply Chain Attack Targeting RedHat npm Packages | Wiz Blog
Detect and mitigate malicious npm packages linked to the latest npm supply chain attack, based on the open sourced Mini Shai-Hulud malware.
originale Part of the PlainSec briefing for 2026-06-04
Every edition of this story: Il worm npm bypassa i controlli sugli script tramite i metadati di build
Altro da oggi