The story of the compromise of 18 NPM packages, which together account for more than 2 billion downloads per week, has continued. A similar phishing attack was detected for the credentials of the DuckDB project, which maintains NPM packages. Versions with malicious code were also created for DuckDB packages, which substituted the details when making payments via cryptocurrency, but the attack was immediately detected and only a few downloads of malicious packages were recorded. At the same time, according to preliminary data, the packages with a malicious insert, published during the attack on 18 NPM packages announced yesterday, managed to be downloaded more than 2.5 million times.
Packages compromised in the second phishing attack:
Source: opennet.ru
