Gipsy Kings: "Music Is a Natural Way of Life"
Section: Arts
A significant supply chain attack has compromised the widely used JavaScript package, is, which records approximately 2.7 million downloads per week. The breach occurred following a phishing incident targeting a maintainer of the npm repository.
According to reports, the account of another maintainer was hijacked, leading to the distribution of malicious payloads within versions 3.3.1 and 5.0.0 of the package. These versions were only available for a brief period before being removed from circulation.
In response to the incident, the maintainer, Jordan Harband, has deprecated the affected versions and released version 3.3.2, free from harmful code, as the latest stable update. This precaution aims to prevent automated processes from inadvertently downloading the infected versions.
The is package serves as a testing library, providing functionalities to check if a value is defined, empty, or of a specific type, among other features.
This incident reflects a broader trend of supply chain vulnerabilities, particularly affecting npm maintainers. The same group of attackers has previously targeted several packages, including eslint-config-prettier and got-fetch, embedding malware into them.
Notably, the malware loader introduced in the is package operates across multiple platforms, including Windows, macOS, and Linux. Security experts have detailed the operation of the malicious JavaScript code, which constructs the payload entirely in the memory of the compromised system. The code executes a remote shell by utilizing a WebSocket connection to communicate with the threat actor's server.
To ensure security, developers using the is package are advised to verify that they do not have any of the infected versions installed. The ongoing threat from these attackers suggests that they may continue to target other JavaScript maintainers in the future.
Section: Arts
Section: Fashion
Section: Travel
Section: Health Insurance
Section: News
Section: Politics
Section: Business
Section: Health
Section: Arts
Section: Business
Both private Health Insurance in Germany and public insurance, is often complicated to navigate, not to mention expensive. As an expat, you are required to navigate this landscape within weeks of arriving, so check our FAQ on PKV. For our guide on resources and access to agents who can give you a competitive quote, try our PKV Cost comparison tool.
Germany is famous for its medical expertise and extensive number of hospitals and clinics. See this comprehensive directory of hospitals and clinics across the country, complete with links to their websites, addresses, contact info, and specializations/services.
Didn't manage to get a ticket for Linkin Park? Or still not enough after the concert? Join us at CRASH on June 12th for our "IN THE END" Linkin Park Special + CORE NIGHT.All night long, we'll be playing Linkin Park's music, along with Nu Metal, Metalcore, and Alternative Rock from bands such as Limp...
No comments yet. Be the first to comment!