A 176-Package NPM Campaign Built to Beat Your Internal Dependencies
Researchers at Sonatype have uncovered a sophisticated NPM supply chain attack involving 176 malicious packages designed to infiltrate internal corporate dependencies. The campaign specifically targets private packages within organizations, aiming to harvest sensitive data and credentials from development environments. This highlights the growing risk to internal, non-public dependencies that many teams mistakenly assume are safe from external threats.