Malicious packages were found cloning legitimate project structures within the npm ecosystem hosted on GitHub.
2 reports, 2 independent
Updated Aug 14
Gone quiet
- Reports
- 2
- Developments
- 2
- Repetition
- 0%
New informationRepeats or wire copies
AI-generated analysis. Brind wrote this summary from the reports listed below. It can be wrong. Each section says how much you can rely on it, and the sources are linked so you can check.
What happened
Malicious packages were found cloning legitimate project structures within the npm ecosystem hosted on GitHub.
Who's involved
What this event is mainly aboutHow it developed
Newest first. Tap a step to see who reported it.Snyk monitored malicious package availability in the npm ecosystem.1 source
Malicious packages were found cloning legitimate project structures on GitHub/npm.1 source
Keep exploring
The entities involved
-
GitHub
hosting service for software projects using Git