SAP / risk-explorer-for-software-supply-chains

A taxonomy of attacks on software supply chains in the form of an attack tree, based on and linked to numerous real-world incidents and other resources. The taxonomy as well as related safeguards can be explored using an interactive visualization tool.
https://sap.github.io/risk-explorer-for-software-supply-chains/
Apache License 2.0
71 stars 14 forks source link

Add new reference to latest phylum discovery #117

Closed piergiorgioladisa closed 2 months ago

piergiorgioladisa commented 4 months ago

Adding the reference to the latest discovery from Phylum about a malicious package in npm named img-aws-s3-object-multipart-copy, mimicking the legitimate package aws-s3-object-multipart-copy to deliver malicious content obfuscated through steganography