Reports from cybersecurity experts reveal an ongoing software supply chain breach that has been operational for more than a year within the npm package registry.
Reports from cybersecurity experts reveal an ongoing software supply chain breach that has been operational for more than a year within the npm package registry. Initially appearing as a harmless library, the attackers later injected harmful code into it to pilfer confidential information and execute cryptocurrency mining operations on compromised devices. The library, identified as @0xengine/xmlrpc, was initially released on October 2, 2023, functioning as a JavaScript-driven XML-RPC implementation.
Andy Curtis is an award-winning security consultant, researcher and public speaker. He has been working in the computer security industry since the early 1990s, having been employed by state and federal government, leading healthcare and banking providers across three continents. He has given talks about computer security for some of the world’s largest companies, worked with law enforcement agencies on investigations into hacking groups, and is a regular voice on TV and radio explaining IT security threats.