Posted inCybersecurity News
Widely-used JavaScript utility package ‘is’ (and others) deliver malware through NPM package system.
In a significant software supply chain breach, the widely-used JavaScript utility package ‘is’, which receives over 2.8 million weekly downloads, was compromised and used to distribute malware through the NPM ecosystem.