FilterHN
new
ask
show
jobs
submit
FilterHN
show menu
Malicious NPM "Sandworm" packages targeting AI toolchains and DevSecOps
2 points
by
nuzzl
1 hour ago
|
past
| 1 comment
|
phoenix.security
|
HN
▲
nuzzl
1 hour ago
[-]
With the recent 'Sandworm' attack involving AI-generated NPM packages, we're seeing a new supply chain vector: developers asking LLMs for library recommendations and getting hallucinated (but real and malicious) package names.
reply