Npm ecosystem vulnerable to new manifest confusion attack
Package manifests in the npm registry are not validated against metadata files in the package itself, leaving the door open for attackers.
Source: csoonline.com
Fast, Ad-Free News Updates
Stay updated with breaking news from Side Enforcement. Real-time updates on events, politics, business and more.