Supply chain attack hits npm package with 45,000 weekly downloads

https://www.bleepingcomputer.com/news/security/supply-chain-attack-hits-npm-package-with-45-000-weekly-downloads/

16 points · 2 comments · view on lemmy.world

2 Comments

qistoph@feddit.nl · 6 pts · 1y (1 reply)

"obfuscated code hidden in the 'dist/index.js' file that was only visible when the user scrolled horizontally"

Malicious intentions aside, surely this is artistic ingenuity

Cyber@feddit.uk · 5 pts · 1y

Wow.

I never knew wordwrap was a vulnerability scanner until now 🤭