monyet.cc
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
@expertmadman@sh.itjust.works to Cybersecurity@sh.itjust.works • 2 years ago

Sophisticated, Highly-Targeted Attacks Continue to Plague npm

sh.itjust.works

message-square
7
fedilink
13

Sophisticated, Highly-Targeted Attacks Continue to Plague npm

sh.itjust.works

@expertmadman@sh.itjust.works to Cybersecurity@sh.itjust.works • 2 years ago
message-square
7
fedilink
alert-triangle
You must log in or register to comment.
  • mo_ztt ✅
    link
    fedilink
    English
    9•2 years ago

    Article? It’s just the image

    • @expertmadman@sh.itjust.worksOP
      link
      fedilink
      7•2 years ago

      I screwed up submission

      https://blog.phylum.io/sophisticated-highly-targeted-attacks-continue-to-plague-npm/

      • mo_ztt ✅
        link
        fedilink
        English
        4•2 years ago

        All good, you can still go back and edit it to fix it.

        • @sugar_in_your_tea@sh.itjust.works
          link
          fedilink
          4•2 years ago

          Yup, this isn’t Reddit.

          • mo_ztt ✅
            link
            fedilink
            English
            2•2 years ago

            Yeah sure, you can edit post titles, but you have to remember that we don’t yet have an unusable chat or a very limited selection of mascot-themed avatars. CHRIST WHAT WERE WE THINKING

            • mo_ztt ✅
              link
              fedilink
              English
              2•
              edit-2
              2 years ago

              Also, why hasn’t he updated the story yet, and why are people upvoting the nonexistent story… I am being 100% sincere when I say that seeing a community of people upvote a story, when the actual link to the story is broken so you can’t read it, makes me rethink what type of people make up that community and whether I want to be a part of it.

              IDK, maybe it’s some federation thing where he updated the story a while ago and the change just doesn’t propagate properly or quickly or something.

              Edit: Nope, not a federation thing, as of T plus 9 hours. What are y’all upvoting?

  • @expertmadman@sh.itjust.worksOP
    link
    fedilink
    5•2 years ago

    https://blog.phylum.io/sophisticated-highly-targeted-attacks-continue-to-plague-npm/

    tl;dr several packages were recently published to npm that appear to be subtle command and control. Behaviors of the infrastructure seem to mimic those recently identified by Phylum as being nation state activity from North Korea.

Cybersecurity@sh.itjust.works

!cybersecurity@sh.itjust.works

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !cybersecurity@sh.itjust.works

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

  • Be respectful. Everyone should feel welcome here.
  • No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
  • No Ads / Spamming.
  • No pornography.

Community Rules

  • Idk, keep it semi-professional?
  • Nothing illegal. We’re all ethical here.
  • Rules will be added/redefined as necessary.

If you ask someone to hack your “friends” socials you’re just going to get banned so don’t do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

  • 111 users / day
  • 529 users / week
  • 1.5K users / month
  • 4.72K users / 6 months
  • 7.37K subscribers
  • 2.94K Posts
  • 5.23K Comments
  • Modlog
  • mods:
  • Kid
  • Lanky_Pomegranate530
  • BE: 0.19.3
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org