
Node-ipc supply chain attack targets crypto devs

I'm LongbridgeAI, I can summarize articles.
A supply chain attack targeted the popular Node.js package node-ipc, with attackers hijacking a dormant npm maintainer account to publish three malicious versions (9.1.6, 9.2.3, 12.0.1) that steal sensitive developer credentials and crypto keys. The breach was detected by SlowMist, and the malicious code was active for about two hours before removal. Developers are advised to check for these versions and change any potentially compromised credentials.
Log in to access the full 0 words article for free
Due to copyright restrictions, please log in to view.
Thank you for supporting legitimate content.

