Global Feed Post Login
Replying to Avatar Mike Dilger ☑️

FYI there is a massive cyberattack on NPM right now, package developers being attacked, nasty commits being added and published, tokens being stolen and used to corrupt more packages. The ecosystem is currently widely corrupted. We just got an advisory from the NZ government about it.

Avatar
Mike Dilger ☑️ 3mo ago 💬 1

https://www.ncsc.govt.nz/alerts/widespread-supply-chain-compromise-impacting-npm-ecosystem/

Reply to this note

Please Login to reply.

Discussion

Avatar
ygrek 3mo ago 💬 1

apparently this is about two weeks old attack, pretty impressive government reaction speed actually

Thread collapsed