EPISODE · Sep 9, 2025 · 8 MIN
SANS Stormcast Tuesday, September 9th, 2025: Major npm compromise; HTTP Request Signature
from SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) · host Dr. Johannes B. Ullrich
Major npm compromise A number of high-profile npm libraries were compromised after developers fell for a phishing email. This compromise affected libraries with a total of hundreds of millions of downloads a week. https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydioq5swk2y https://github.com/orgs/community/discussions/172738 https://github.com/chalk/chalk/issues/656#issuecomment-3266894253 https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised HTTP Request Signatures It looks like some search engines and AI bots are starting to use the HTTP request signature. This should make it easier to identify bot traffic. https://isc.sans.edu/diary/HTTP%20Request%20Signatures/32266
What this episode covers
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Tuesday, September 9th, 2025: Major npm compromise; HTTP Request Signature
NOW PLAYING
SANS Stormcast Tuesday, September 9th, 2025: Major npm compromise; HTTP Request Signature
No transcript for this episode yet
Similar Episodes
Mar 26, 2026 ·1m
Jan 2, 2026 ·47m
Dec 21, 2025 ·46m