• morgunkorn@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    10
    ·
    3 days ago

    A significant supply chain attack hit NPM after 17 popular Gluestack ‘@react-native-aria’ packages with over 1 million downloads were compromised to include malicious code that acts as a remote access trojan (RAT).

    • Phen@lemmy.eco.br
      link
      fedilink
      English
      arrow-up
      3
      ·
      3 days ago

      The malware is not on react-native, but react-native-aria. A “copy” of Adobe’s react-aria libs.

  • corsicanguppy@lemmy.ca
    cake
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 days ago

    Is this a new one or is this last week’s? It’s hard to keep the weekly supply chain 'sploits straight. Feed your leopards, kids.