News Score: Score the News, Sort the News, Rewrite the Headlines

Here’s how carefully concealed backdoor in fake AWS files escaped mainstream notice

DEVS IN THE CROSSHAIRS — Files available on the open source NPM repository underscore a growing sophistication. Researchers have determined that two fake AWS packages downloaded hundreds of times from the open source NPM JavaScript repository contained carefully concealed code that backdoored developers' computers when executed. The packages—img-aws-s3-object-multipart-copy and legacyaws-s3-object-multipart-copy—were attempts to appear as aws-s3-object-multipart-copy, a legitimate JavaScript ...

Read more at arstechnica.com

© News Score  score the news, sort the news, rewrite the headlines