search
SafeDep
Trends
- 1PolinRider Malware Uses Ethereum Blockchain to Control Infected GitHub Repositories●(safedep.io) PolinRider Malware Leverages Ethereum Blockchain for Command and Control in GitHub Supply Chain Attack In b
Security researchers have detailed PolinRider, a loader family that infected more than 30 GitHub repositories in a supply chain attack aimed at stealing environment secrets. The malware stands out for using the Ethereum blockchain as its command-and-control channel, making its infrastructure harder to take down. Cybersecurity commentators are sharing the analysis as a warning to developers to audit dependencies and protect stored secrets.
- 2DirtyBlanket Linux Worm Spreads Through Malicious npm Packages●(safedep.io) DirtyBlanket: Self-Spreading Linux Worm Distributed via Malicious npm Packages Targeting Developers In brie
Security researchers at SafeDep report a self-spreading Linux worm, dubbed DirtyBlanket, distributed through nine malicious npm packages impersonating popular libraries such as Express and React. Once installed, the malware targets developers' Linux machines and propagates further, making supply-chain attacks on the JavaScript ecosystem a renewed concern for developers reviewing dependencies.