Npm ecosystem vulnerable to new manifest confusion attack
Package manifests in the npm registry are not validated against metadata files in the package itself, leaving the door open for attackers.
Source: csoonline.com
Stay updated with breaking news from Side Enforcement. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Package manifests in the npm registry are not validated against metadata files in the package itself, leaving the door open for attackers.