cybersecurity
Atomic Arch npm Campaign Adds Malicious Dependency
Source:
sonatype.com 1 min read
Share
You are reading a summary. The full content is hosted on sonatype.com.
Sonatype researchers identified Atomic Arch, a campaign that takes over orphaned Arch User Repository packages and alters PKGBUILDs to install a malicious npm dependency during installation. The dependency, atomic-lockfile, includes a Linux payload linked to credential harvesting, stealth, anti-debugging, and possible data exfiltration.
Read the full article on the original website
External link to sonatype.com