Only 9.27% of NPM package maintainers use two-factor authentication.

Adam Baldwin, leading the team responsible for the security of the NPM repository, announced statistics prepared based on last year's results:

  • Despite ongoing incidents involving the takeover of NPM repositories, only 9.27% of package maintainers use two-factor authentication to secure access;
  • Upon registration, 13.37% of new accounts attempted to reuse compromised passwords that appeared in known password leaks according to the service data. haveibeenpwned.com;
  • Last year, 737 NPM tokens were revoked, which were mistakenly has been published in the NPM package registry or publicly accessible repositories on GitHub;
  • Prevented the theft of $13 million in cryptocurrency, thanks to the identification of an attempt to integrate a backdoor into the Komodo Agama wallet;
  • The total number of reports about security issues in the NPM database reached 1285, of which 595 reports were prepared in 2019. A total of 2.2 thousand notifications about vulnerabilities were received via security@npmjs.com;
  • Over the year, the anti-spam system blocked 11,526 transactions, including those related to attempts to promote torrent and movie advertising;
  • The anomaly detection system generated 1.4 million reports, requested through the API, covering 15.6 TB of data containing behavioral analysis information. 🥇Only 9.27% of NPM package maintainers use two-factor authentication | ProHoster

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster