Hacker News
new
top
best
ask
show
job
Malicious NPM "Sandworm" packages targeting AI toolchains and DevSecOps
(
phoenix.security
)
2 points
by
nuzzl
6 hours ago
1 comment
nuzzl
6 hours ago
With the recent 'Sandworm' attack involving AI-generated NPM packages, we're seeing a new supply chain vector: developers asking LLMs for library recommendations and getting hallucinated (but real and malicious) package names.