Rising security concerns as hackers leverage an old-school weapon: the ‘Shift’ key to exploit npm packages
Exploiting typos with malicious intent: npm’s vulnerability Recently published research from Checkmarx has shed light on a long-standing vulnerability in npm, the package manager for the JavaScript programming language. Since 2017, malicious actors have been able to use typosquatting to mimic legitimate npm packages by subtly changing the capitalisation of letters in their titles. npm’s…