1427 - Ransomware packages in PyPI and NPM

Modified on Mon, 21 Jul at 12:55 PM

Background

On 9 December 2022, a number of malicious packages targeted at Python and JavaScript developers were discovered in PyPI and NPM. Details can be found here.

 

Mitigation

Some of Redstor's software development is done in JavaScript. We use software composition analysis (SCA) tools to monitor vulnerabilities in our code base. We have not been affected by this ransomware campaign thus far. In the interest of security, we have made our developers aware of the risk.

 

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article