Adam Baldwin, leading the team responsible for the security of the NPM repository, statistics prepared based on last year's results:
- Despite involving the takeover of NPM repositories, only 9.27% of package maintainers use two-factor authentication to secure access;
- Upon registration, 13.37% of new accounts attempted to reuse compromised passwords that appeared in known password leaks according to the service data. ;
- Last year, 737 NPM tokens were revoked, which were mistakenly in the NPM package registry or publicly accessible repositories on GitHub;
- the theft of $13 million in cryptocurrency, thanks to the identification of an attempt to integrate a backdoor into the Komodo Agama wallet;
- The total number of reports about security issues in the NPM database reached 1285, of which 595 reports were prepared in 2019. A total of 2.2 thousand notifications about vulnerabilities were received via security@npmjs.com;
- Over the year, the anti-spam system blocked 11,526 transactions, including those related to attempts to promote torrent and movie advertising;
- The anomaly detection system 🥇Only 9.27% of NPM package maintainers use two-factor authentication | ProHoster
Source: opennet.ru
