2023-03-31
BleepingComputer
32 related
Researchers say hackers have compromised the VoIP desktop client of 3CX's Phone System, used by 600K+ companies and 12M+ DAUs, in an ongoing supply chain attack
https://www.3cx.com/... Any vendor of software and services that pull in code from NPM, PIP, RubyGems etc … Eitan Erez : This supply chain attack started unfolding not long ago as 3CX VOIP desktop cl...
2022-01-10
BleepingComputer
9 related
An open-source developer, expressing regret for supporting “Fortune 500s”, breaks ~19K projects by corrupting popular NPM libraries; GitHub reverts the changes
Users of popular open-source libraries ‘colors’ and ‘faker’ were left stunned after they saw their applications …
2016-03-23
The Register
1 related
Thousands of web apps dependent on JavaScript module Left-Pad broken for a few hours after developer yanks it from NPM in protest
How one developer just broke Node, Babel and thousands of projects in 11 lines of JavaScript — left-pad pulled from NPM - which everyone was using
Loading articles...