Blogs

New npm Flaws Let Attackers Better Target Packages for Account Takeover

Aquasec

For the past few years, cybercriminals have been hijacking popular npm packages by taking over maintainers’ accounts.

Visit Site

Blogs Aquasec

BlogsDeceptive Deprecation: The Truth About npm Deprecated PackagesAquasec BlogsThreat Alert: Private npm Packages Disclosed via Timing AttacksAquasec BlogsPowerHell: Active Flaws in PowerShell Gallery Expose Users to AttacksAquasec BlogsTracee Release: Rules Detect Attackers Out-of-the-BoxAquasec BlogsCloud Workload Security: Aqua Shines in GigaOm's Radar ReportAquasec BlogsAqua and HashiCorp Enable Cloud Native Security, Zero-Trust ApproachesAquasec ResourcesWhat is Workflow Automation?Datadoghq BlogsA Big Chip for Big Science: Watching the COVID-19 Virus in Action - CerebrasCerebras ResourcesNEXTJS_MISSING_MODULARIZE_IMPORTSVercel ResourcesHow to Fully Delete a Git Repository Created with Init? | Better Stack CommunityBetterstack ResourcesHow to assign a port mapping to an existing Docker container? | Better Stack CommunityBetterstack ResourcesDefault Behavior of “Git Push” without a Branch SpecifiedBetterstack BlogsSurveyMonkey automation with ZapierZapier BlogsHow to Protect Your Projects from the Risks of Deprecated npm PackagesSocket NewsWhen "Everything" Becomes Too Much: The npm Package Chaos of 2024Socket BlogsPolinRider Spreads Through Compromised GitHub Accounts and PackagistSocket BlogsPopular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain AttackSocket BlogsCleaning up import paths in JS/TS packagesSocket BlogsSupply Chain Attack on Axios Pulls Malicious Dependency from npmSocket BlogsVisualize CSV Data and Build a Dashboard to Track Your Amazon SpendingRetool