Comments

Somebody Tried to Hide a Backdoor in a Popular JavaScript npm Package

Somebody Tried to Hide a Backdoor in a Popular JavaScript npm Package
Published on May 03, 2018 at 03:20PM
Catalin Cimpanu, reporting for BleepingComputer: The Node Package Manager (npm) team avoided a disaster today when it discovered and blocked the distribution of a cleverly hidden backdoor mechanism inside a popular -- albeit deprecated -- JavaScript package. The actual backdoor mechanism was found in "getcookies," a relatively newly created npm package (JavaScript library) for working with browser cookies. The npm team -- which analyzed this package earlier today after reports from the npm community -- says "getcookies" contains a complex system for receiving commands from a remote attacker, who could target any JavaScript app that had incorporated this library.

Read more of this story at Slashdot.





Hope you like this please comment your view and share to your friends thanks for visiting bye guys meet you in next post
Somebody Tried to Hide a Backdoor in a Popular JavaScript npm Package Somebody Tried to Hide a Backdoor in a Popular JavaScript npm Package Reviewed by Kartik on May 03, 2018 Rating: 5

No comments:

Ad

Powered by Blogger.