Blog

Follow for the latest updates and insights on
open source security & engineering.

@fairwords npm Packages Hit by Credential Worm

@fairwords npm Packages Hit by Credential Worm

Three @fairwords npm packages were compromised with a self-propagating worm that harvests credentials, crypto wallets, Chrome passwords, and spreads to other packages using stolen npm tokens.

SafeDep Team
Background
SafeDep Logo

Ship Code.

Not Malware.

Start free with open source tools on your machine. Scale to a unified platform for your organization.