TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Fake Developer Jobs Laced with Malware

5 pointsby pcloadletter_over 1 year ago

1 comment

pcloadletter_over 1 year ago
Sounds like the attacker is getting pretty smart about this stuff too. They have a self-hosted registry with the offending package so it can&#x27;t get yanked from the actual npm registry<p>&gt;The attackers now host the attack from mave-finance&#x2F;next-assessment. The malicious dependency is json-mock-config-server which is not listed in the npm registry, but rather is served from npm.mave.finance as before, the registry listed in .npmrc.