GitHub is an useful development and versioning environment – part of it’s growth was to acquire another similar service NPM – a software depository. The software depository is now under possible attack from the simple of threat actors offering malicious packages with names that are just slightly different from the legitimate packages. It’s called typo-squatting and often happens with popular websites as well – www.mucrosoft.com (my example I am not sure of it’s provenance?).
The unwary or those in a hurry may not notice the difference – and show me a software developer who is not in a hurry, could down load the mistyped package in error. If this malicious package is a module that the developer then includes in their code and package, well you can see why the threat actors reckon this is a good attack vector.
Light shone on typo-squatting NPM supply chain attack • The Register
Further Reading
Clive Catton MSc (Cyber Security) – by-line and other articles
Please Note:
I am on leave so the news this week is “in brief”. You can still contact me via the contact page and Octagon Technology.