Exploitation of Nine-Year-Old npm Components for Extracting API Keys Using Camouflaged Codes

A group of cybersecurity analysts identified a number of virtual currency components in the npm catalog that have been taken over to extract critical data like system variables from infiltrated networks.

A group of cybersecurity analysts identified a number of virtual currency components in the npm catalog that have been taken over to extract critical data like system variables from infiltrated networks.
“Several of these components have existed on npmjs.com for more than 9 years, and offer valid features to blockchain programmers,” noted Ax Sharma, a researcher from Sonatype. “Nevertheless, […] the most recent”

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.