npm SANDWORM_MODE Attack: Step-by-Step Malware Analysis

1 min read Original article ↗

14 min read

Table of Contents

  • npm
  • supply-chain
  • security
  • malware-analysis

Author

SafeDep Logo

Share

The Latest from SafeDep blogs

Follow for the latest updates and insights on open source security & engineering

Malicious Pull Requests: A Threat Model

Malicious Pull Requests: A Threat Model

A compact threat model of the malicious pull request as a supply chain attack primitive against GitHub Actions: attacker, goals, assets, controllable surface, and an attack vector taxonomy (V1...

Background

SafeDep Logo

Ship Code.

Not Malware.

Start free with open source tools on your machine. Scale to a unified platform for your organization.