Dossier
supply-chain attacks
Coverage of supply-chain attacks in the Nexus archive.
- The ‘Miasma’ worm source code briefly leaked on GitHub
The Miasma credential-stealing attack framework's source code was briefly leaked on GitHub. It has been used to target open-source ecosystems through supply-chain attacks.
- GitHub announces npm security changes to tackle supply-chain attacks
GitHub has announced npm v12 will introduce security-focused changes to block supply-chain attacks exploiting the 'npm install' command. The updates aim to prevent malicious behaviors triggered by this command.