Hundreds of malware-laden fake npm packages posted online to try and trick developers
When you purchase through links on our site, we may earn an affiliate commission.Heres how it works. The packages are typosquatted versions of Puppeteer and Bignum.js. The binary shipped to the machine is a packed Vercel package, the researchers explained. (Image credit: Shutterstock) An apparent oversight by the malicious package author, they say. This is, once again, a persistent reminder that supply chain attacks are alive and well. The IP cannot be seen in the first-stage code....