paint-brush
Over 35 Tech Companies Compromised in Novel Software Supply Chain Attackby@sonatype
459 reads
459 reads

Over 35 Tech Companies Compromised in Novel Software Supply Chain Attack

by sonatype7mApril 25th, 2022
Read on Terminal Reader
Read this story w/o Javascript
tldt arrow

Too Long; Didn't Read

Security researcher Alex Birsan breached systems of over 35 tech companies in what has been described as a novel software supply chain attack. The attack is of particular significance as unlike traditional typosquatting or brandjacking supply-chain attacks that Sonatype has talked about before, the targeted companies automatically received Birsan’s malicious packages without them making any spelling mistakes, or any social engineering involved. For demonstrating the seriousness of this type of attack, Birsan has been awarded upwards of $130,000 in bug bounties.

Companies Mentioned

Mention Thumbnail
Mention Thumbnail

Coin Mentioned

Mention Thumbnail
featured image - Over 35 Tech Companies Compromised in Novel Software Supply Chain Attack
sonatype HackerNoon profile picture
sonatype

sonatype

@sonatype

Find and fix critical security, performance, reliability, and style issues in developer code.

L O A D I N G
. . . comments & more!

About Author

sonatype HackerNoon profile picture
sonatype@sonatype
Find and fix critical security, performance, reliability, and style issues in developer code.

TOPICS

THIS ARTICLE WAS FEATURED IN...

Permanent on Arweave
Read on Terminal Reader
Read this story in a terminal
 Terminal
Read this story w/o Javascript
Read this story w/o Javascript
 Lite
Also published here
100yenmac
Newsbreak
Dasnetzundich
Nitter
Nutter
Moomoo
Numblr
Ktachibana
Saty
Platypush
Trom