Get the latest tech news

Unverified NPM Account Takeover Vulnerability for Sale on Dark Web Forum


A threat actor on BreachForums is selling an unverified npm vulnerability for account takeover, but npm has not officially confirmed the existence of this security concern.

Dark Web Informer is reporting a threat actor is selling a critical, unverified npmjs vulnerability that would allegedly allow for account takeover. It’s the gateway to the wide world of applications that depend on open source JavaScript, attracting threat actors who relentlessly target npmjs accounts for distributing malicious code. Package authors and organizations using npm should monitor their accounts for unusual activity, maintain the registration of the domains associated with their email addresses, and use strong, unique passwords.

Get the Android app

Or read this on Hacker News

Read more on:

Photo of sale

sale

Photo of unverified npm

unverified npm

Photo of dark web forum

dark web forum

Related news:

News photo

Elgato’s new Stream Deck is on sale for the first time and $15 off

News photo

Amazon’s last-gen Kindle Paperwhite is on sale for 50 bucks right now

News photo

Dragon's Dogma 2 free trial and sale now available