Top stories.
- Major npm supply chain attack has been largely averted.
- Attackers send phishing messages via iCloud Calendar invites.
- US Treasury sanctions Southeast Asian scam networks.
Major npm supply chain attack has been largely averted.
Attackers launched a widespread supply chain attack yesterday after hacking an npm developer's account, though the campaign isn't as serious as some initial reports suggested, Infosecurity Magazine reports. Package maintainer Josh Junon confirmed yesterday that his npm account was compromised after he received a phishing email posing as a 2FA reset notification. The hackers then used Junon's "qix" npm account to publish malicious versions of dozens of packages Junon had maintained, which collectively receive more than 2.6 billion weekly downloads. The malicious code monitored the user's web browser for cryptocurrency addresses and replaced them with attacker-controlled addresses.
Less than four hours after Junon disclosed the hack, npm confirmed that all the malicious package versions had been shut down. Observers say the quick response highlighted the strength of the open-source security model. Arda Büyükkaya from EclecticIQ notes that npm recorded zero downloads of the malicious packages, and the attacker's cryptocurrency account currently has a balance of only sixty-six dollars.

