
How 56 npm packages used binding.gyp to steal secrets
The attack is notable for its breadth, flooding npm with malicious package versions.
-300x361.png&w=640&q=75)

The attack is notable for its breadth, flooding npm with malicious package versions.

RL has discovered a new supply chain attack affecting 9.8M total downloads across Red Hat's Hybrid Cloud Console JavaScript ecosystem.
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free Trial