Newly Identified Dependency Confusion Packages Target Amazon, Zillow, and Slack; Go Beyond Just Bug Bounties

new dependency confusion packages published to the npm ecosystem are malicious in nature.

Sonatype has identified new “dependency confusion” packages published to the npm ecosystem that are malicious in nature.

Article Link: https://blog.sonatype.com/malicious-dependency-confusion-copycats-exfiltrate-bash-history-and-etc-shadow-files