DevSec Station

Emergency DevSec Station drop: NPM Worm in the Wild


Listen Later

🚨 Emergency DevSec Station drop.
There's an active npm supply chain attack happening right now. Compromised packages are stealing SSH keys, AWS credentials, GitHub tokens, browser passwords, and crypto wallets on install. Then using your publish token to infect every package you maintain.
One command can protect you immediately: npm config set ignore-scripts true
Do it today, please. Tell your team. Watch the full 60 seconds.
#AppSec #SupplyChainSecurity #DevSecOps #SecureCoding #npm

...more
View all episodesView all episodes
Download on the App Store

DevSec StationBy Tanya Janca | SheHacksPurple