Phylum Research Team
Hackers, Data Scientists, and Engineers responsible for the identification and takedown of software supply chain attackers.
Yesterday, Phylum's automated risk detection platform discovered that the PyPI package aiocpa was updated to include malicious code that steals private keys by exfiltrating them through Telegram when users initialize the crypto library. While
Q3 2024 Evolution of Software Supply Chain Security Report
Software supply chain security faces sophisticated security threats in the open-source ecosystem. Phylum analyzed millions of packages & files. Read more.
Typosquat Campaign Targeting npm Developers
Malware authors have published dozens of typosquat npm packages targeting users of the popular Puppeteer library.
Trojanized Ethers Forks on npm Attempting to Steal Ethereum Private Keys
Software supply chain attack targets open-source developers in npm via malicious packages that steal Ethereum private keys, gain SSH persistence.
North Korea Still Attacking Developers via npm
There's a renewed surge of attacks with obfuscated JavaScript and fake job campaigns to compromise developers and infiltrate companies. See Phylum research.