As cited
Copy frozen at (site build).
Risky Bulletin: Damaging worm rips through npm ecosystem
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
Risky Bulletin: Damaging worm rips through npm ecosystem
A worm spread through the npm package repository, representing another major supply chain attack on the JavaScript ecosystem. Separately, RubyGems disabled new account sign-ups following an attack targeting staff, Instructure paid a ransom demand, and the Gentlemen ransomware group itself fell victim to a breach.
Why it matters: Developers relying on npm packages face ongoing risks from malicious code in the supply chain; RubyGems users and maintainers should monitor for account compromise during the sign-up suspension; Instructure customers should assess ransomware exposure if their data was accessed before payment.
- Source published
- First seen by Cybersecurity Tracker