Hijacking S3 Buckets: New Attack Technique

Open link in next tab

Hijacking S3 Buckets: New Attack Technique

https://checkmarx.com/blog/hijacking-s3-buckets-new-attack-technique-exploited-in-the-wild-by-supply-chain-attackers/?

Without altering a single line of code, attackers poisoned the NPM package “bignum” by hijacking the S3 bucket serving binaries necessary for its function and replacing them with malicious ones

Hijacking S3 Buckets: New Attack Technique

It seems like attackers have discovered a way to leverage NPM packages to deliver malicious binaries without needing to make any changes to the NPM package itself.

See all comments

Interesting! I wonder how much of this is already happening that people just haven't noticed yet.