The Vercel security and compute teams have conducted an investigation into the malicious takeover of the ๐๐ก๐๐๐@๐ท.๐ท๐บ.๐ท npm package.
โข Weโve blocked outgoing access from our build infrastructure to the Command & Control hostname ๐๐๐๐๐๐๐.๐๐๐.
โข The malicious version of the package has been blocked and unpublished from npm.
โข Vercelโs own infrastructure and applications have been unaffected.
โข We recommend checking your supply chain for exposure.
For more information, read the full advisory โ
From Twitter
Disclaimer: The content above is only the author's opinion which does not represent any position of Followin, and is not intended as, and shall not be understood or construed as, investment advice from Followin.
Like
Add to Favorites
Comments
Share
Relevant content





