Researcher’s audacious hack demonstrates new type of supply-chain attack
Malwarebytes
FEBRUARY 11, 2021
They will look for dependencies locally, on the computer where a project resides, and they will check the package manager’s public, Internet-accessible, directory. The most gratifying part of this method is that it does not rely on social engineering. Version confusion.
Let's personalize your content