« 2024 »

654 reports

2024-07-08 • Phylum

Phylum reports a North Korea-linked open-source supply chain campaign that weaponized npm by publishing call-blockflow, a near-copy of the legitimate call-bind package, on 4 July 2024 before it was quickly unpublished. The attacker changed package.json to…

#NPM