Warning: JavaScript registry npm vulnerable to ‘manifest confusion’ abuseThomas Claburnon June 27, 2023 at 20:40 The Register

0

Failure to match metadata with packaged files is perfect for supply chain attacks

The npm Public Registry, a database of JavaScript packages, fails to compare npm package manifest data with the archive of files that data describes, creating an opportunity for the installation and execution of malicious files.…

Leave a Comment