New npm Packages Stealing SSH Keys

The Sonatype Security Research team is currently tracking an ongoing campaign on the npm registry that uses npm packages to retrieve and exfiltrate your Kubernetes configuration and SSH keys to an external server.

npm packages caught exfiltrating Kubernetes config, SSH keys

Great. I wonder what else is going on.

Via https://blog.sonatype.com/npm-packages-caught-exfiltrating-kubernetes-config-ssh-keys

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.