Skip to content

Latest commit

 

History

History
26 lines (19 loc) · 1.48 KB

README.md

File metadata and controls

26 lines (19 loc) · 1.48 KB

SupplyChainSecurity

  • Malicious Packages and Users are infiltrating software around the globe. Examples of Account Takeover, Dependency Confusion, Hacktivism and Chain/Repo-Jacking are being used to infect your software. This repository highlights some of the key Supply Chain flaws that Checkmarx can help you uncover before it's too late.

Account Take Over (Good Packages Gone Bad)

Dependency Confusion

TypoSqutting

ChainJacking (Go / Swift)

Hacktisim/Protetsware

  • node-ipc_9.2.2
  • "Don't trust code from strangers" or more importantly, should you trust contributers who have a questioanble past? RIAEvangelist was responsible for a Hacktivism act against the Russian/Ukraine War introducing a "Peacenotwar" package in NPM - node-ipc_9.2.2. They also maintain 40+ other Open Source projects like event-pubsub (not malicious)
  • https://checkmarx.com/blog/protestware-politics-and-open-source-software/