Fresh Wave of Malicious npm Packages Threaten Kubernetes Configs and SSH Keys
Fresh Wave of Malicious npm Packages Threaten Kubernetes Configs and SSH Keys
20 September 2023
Cybersecurity researchers have discovered a fresh batch of malicious packages in the npm package registry that are designed to exfiltrate Kubernetes configurations and SSH keys from compromised machines to a remote server.
Sonatype said it has discovered 14 different npm packages so far: @am-fe/hooks, @am-fe/provider, @am-fe/request, @am-fe/utils, @am-fe/watermark, @am-fe/watermark-core,