Hijacking S3 Buckets: New Attack Technique
It seems like attackers have discovered a way to leverage NPM packages to deliver malicious binaries without needing to make any changes to the NPM package itself.
https://checkmarx.com/blog/hijacking-s3-buckets-new-attack-technique-exploited-in-the-wild-by-supply-chain-attackers/?Open linkView original on sh.itjust.works
1 reply
Interesting! I wonder how much of this is already happening that people just haven't noticed yet.