Cybersecurity researchers have reported a supply chain attack targeting popular npm packages through a phishing campaign aimed at stealing maintainers’ npm tokens. These stolen tokens were exploited to publish malicious package versions directly to the registry, bypassing the usual GitHub commit and pull request processes.
Explain It To Me Like I’m 5:
Cybersecurity Alert
Researchers have found a supply chain attack targeting popular npm packages through a phishing campaign that steals maintainers’ npm tokens to publish malicious versions directly to the registry.