Security
Headlines
HeadlinesLatestCVEs

Headline

Malicious Nx Packages in ‘s1ngularity’ Attack Leaked 2,349 GitHub, Cloud, and AI Credentials

The maintainers of the nx build system have alerted users to a supply chain attack that allowed attackers to publish malicious versions of the popular npm package and other auxiliary plugins with data-gathering capabilities. "Malicious versions of the nx package, as well as some supporting plugin packages, were published to npm, containing code that scans the file system, collects credentials,

The Hacker News
#nodejs#git#The Hacker News

The Hacker News: Latest News

Researchers Find VS Code Flaw Allowing Attackers to Republish Deleted Extensions Under Same Names