× News Alerts AI News CyberSec News Let's Talk Local AI Bank Tech News Cyber Advisories Contact

Popular npm linter packages hijacked to drop malware via phishing

Popular JavaScript libraries eslint-config-prettier and eslint-plugin-prettier were hijacked this week and turned into malware droppers, in a supply chain attack achieved via targeted phishing and credential theft. The attackers managed to gain control of these packages and use them to distribute malware to developer machines. This poses a serious threat to the security of software projects that rely on these libraries.

Popular npm linter packages hijacked to drop malware via phishing

This week, a supply chain attack, executed through targeted phishing and credential theft, led to the compromise of the widely used JavaScript libraries, eslint-config-prettier and eslint-plugin-prettier. These popular components were subsequently converted into malware droppers.

After gaining unauthorized access to these packages, the attackers proceeded to disseminate malicious software onto developer machines. This incident represents a significant risk to the integrity of software projects that are dependent on these libraries. Consequently, users are strongly advised to inspect their systems for any indicators of compromise and to implement robust measures to safeguard their credentials.

Subscribe for AI & Cybersecurity news and insights