Researchers say they’ve discovered a supply-chain attack flooding repositories with malicious packages that contain invisible code, a technique that’s flummoxing traditional defenses designed to detect such threats. The researchers, from firm Aikido Security, said Friday that they found 151 malicious packages that were uploaded to GitHub from March 3 to March 9. Such supply-chain attacks have been common for nearly a decade . They usually work by uploading malicious packages with code and names that closely resemble those of widely used code libraries, with the objective of tricking developers into mistakenly incorporating the former into their software. In some cases, these malicious packages are downloaded thousands of times. Defenses see nothing. Decoders see executable code The packages Aikido found this month have adopted a newer technique: selective use of code that isn’t visible when loaded into virtually all editors, terminals, and code review interfaces. While most of the...
Search This Blog
Lagos Writer
News feed, music updates, tech news, and so much more.
Posts
Featured
Latest posts
Posted by
Too Simpu
Romania’s Eurovision entry criticised for allegedly “glamorising sexual strangulation”
- Get link
- X
- Other Apps
Posted by
Too Simpu
60 Minutes: We've Had the Havana Syndrome Weapon for More Than a Year
- Get link
- X
- Other Apps
Posted by
Too Simpu
The who, what, and why of the attack that has shut down Stryker's Windows network"
- Get link
- X
- Other Apps
Posted by
Too Simpu
Sales automation startup Rox AI hits $1.2B valuation, sources say
- Get link
- X
- Other Apps
Posted by
Too Simpu
Man Who Shoved Two People Onto Subway Tracks Had Been Deported Four Times
- Get link
- X
- Other Apps
Posted by
Too Simpu
India neobank Fi winds down banking services on its platform
- Get link
- X
- Other Apps
Posted by
Too Simpu
Yet Another CNN Reporter Steps on the Rake
- Get link
- X
- Other Apps
Posted by
Too Simpu
FDA contradicts Trump admin, declines to approve generic drug for autism
- Get link
- X
- Other Apps
Posted by
Too Simpu
In a vote of confidence for Meta’s Threads, Kalshi adds sharing feature
- Get link
- X
- Other Apps
Posted by
Too Simpu
LA County is 'Ground Zero' for Hospice Fraud
- Get link
- X
- Other Apps