Researcher hacks over 35 tech firms in novel supply chain at

Researcher hacks over 35 tech firms in novel supply chain attack -- Science & Technology -- Sott.net


Tue, 09 Feb 2021 18:04 UTC
A researcher managed to breach over 35 major companies' internal systems, including Microsoft, Apple, PayPal, Shopify, Netflix, Yelp, Tesla, and Uber, in a novel software supply chain attack.
The attack comprised uploading malware to open source repositories including PyPI, npm, and RubyGems, which then got distributed downstream automatically into the company's internal applications.
Unlike traditional typosquatting attacks that rely on social engineering tactics or the victim misspelling a package name,
this particular supply chain attack is more sophisticated as it needed no action by the victim, who automatically received the malicious packages.
This is because the attack leveraged a unique design flaw of the open-source ecosystems called

Related Keywords

Alex Birsan , Dustin Ingram , Justin Gardner , Birsan Hackerone , Google , Yelp , Python Software Foundation , Netflix , Microsoft , Azure Artifactory , Azure Artifacts , Apple Security Bounty , Nexus Repository Manager , டஸ்டின் இஂக்ரம் , ஜஸ்டின் கார்ட்னர் , கூகிள் , கத்தவும் , பைதான் மென்பொருள் அடித்தளம் , நெட்ஃபிக்ஸ் , மைக்ரோசாஃப்ட் , நீலமான கலைப்பொருள் , நீலமான கலைப்பொருட்கள் , ஆப்பிள் பாதுகாப்பு பவுண்டரி , நெக்ஸஸ் களஞ்சியம் மேலாளர் ,

© 2025 Vimarsana