Microsoft Successfully Hit by A Dependency Hijacking Attack Again

2 years ago 45
BOOK THIS SPACE FOR AD
ARTICLE AD

29. June 2021

This article has been indexed from Heimdal Security Blog

Today, news broke that security researcher Ricardo Iramar dos Santos found an npm internal dependency while auditing an open-source SymphonyElectron package for bugs. Although the dependency was called “swift-search,” this package wasn’t present on the public npmjs.com registry. Using his custom code, dos Santos registered a package by the same name on the npm registry. […]

The post Microsoft Successfully Hit by A Dependency Hijacking Attack Again appeared first on Heimdal Security Blog.

Read the original article: Microsoft Successfully Hit by A Dependency Hijacking Attack Again

Read Entire Article