Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • A Blockchain-based Crypto Economy Where Content Creators Are Offered Freedom, Control & Unlimited Earning Potential bitcoin news
  • Rich Dad Poor Dad’s Robert Kiyosaki Plans to Buy Bitcoin When the ‘Bottom Is In’ — Says It Could Be at $17K – Bitcoin News bitcoin news
  • Bitcoin․com Exchange Market Insights Report for May 2022 – Promoted Bitcoin News bitcoin news
  • Perp Traders Remain Quiet As Bitcoin Struggles To Hold $30,000 bitcoin news
  • North Korean Hackers Target Journalists with GOLDBACKDOOR Malware cyber security news
  • ETC Climbs to 1-Week High, as AXS Moves Away From 10-Month Low – Market Updates Bitcoin News bitcoin news
  • ESG Study Shows Bitcoin Mining’s Potential to Eliminate 0.15% of Global Warming by 2045, Claims No Other Technology Can Do Better – Mining Bitcoin News bitcoin news
  • Cyprus Drafts Crypto Rules, May Introduce Them Before EU Regulations – Regulation Bitcoin News bitcoin news

Here’s a New Tool That Scans Open-Source Repositories for Malicious Packages

Posted on May 2, 2022 By root No Comments on Here’s a New Tool That Scans Open-Source Repositories for Malicious Packages


Malicious Packages in Open-Source Repositories

The Open Source Security Foundation (OpenSSF) has announced the initial prototype release of a new tool that’s capable of carrying out dynamic analysis of all packages uploaded to popular open source repositories.

Called the Package Analysis project, the initiative aims to secure open-source packages by detecting and alerting users to any malicious behavior with the goal of bolstering the security of the software supply chain and increasing trust in open-source software.

“The Package Analysis project seeks to understand the behavior and capabilities of packages available on open source repositories: what files do they access, what addresses do they connect to, and what commands do they run?,” the OpenSSF said.

“The project also tracks changes in how packages behave over time, to identify when previously safe software begins acting suspiciously,” the foundation’s Caleb Brown and David A. Wheeler added.

In a test run that lasted a month, the tool identified more than 200 malicious packages uploaded to PyPI and NPM, with a majority of the rogue libraries leveraging dependency confusion and typosquatting attacks.

Google, which is a member of OpenSSF, has also rallied its support behind the Package Analysis project, while emphasizing the need for “vetting packages being published in order to keep users safe.”

CyberSecurity

The tech giant’s Open Source Security Team, last year, put forth a new frame called Supply chain Levels for Software Artifacts (SLSA) to ensure the integrity of software packages and prevent unauthorized modifications.

The development comes as the open source ecosystem is being increasingly weaponized to target developers with a variety of malware, including cryptocurrency miners and information stealers.





TheHackersNews/

cyber security news

Post navigation

Previous Post: Bitcoin Struggles To Hold $40K While Crypto Track US Stocks
Next Post: Samsung Group Investment Arm to List Blockchain ETF on Hong Kong Exchange – Finance Bitcoin News

Related Posts

  • Bitter APT Hackers Add Bangladesh to Their List of Targets in South Asia cyber security news
  • The Added Dangers Privileged Accounts Pose to Your Active Directory cyber security news
  • PayPal Pays a Hacker $200,000 for Discovering ‘One-Click-Hack’ Vulnerability cyber security news
  • Fake Clickjacking Bug Bounty Reports: The Key Facts cyber security news
  • This New Fileless Malware Hides Shellcode in Windows Event Logs cyber security news
  • SIM-based Authentication Aims to Transform Device Binding Security to End Phishing cyber security news

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Archives

  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Sequel to Iconic RPG Ni No Kuni to Feature NFT Integration and Play-to-Earn Mechanics – News Bitcoin News
  • India’s Central Bank RBI to Adopt a ‘Graded Approach’ to Digital Currency Launch – Regulation Bitcoin News
  • Ethereum Slips, What Are The Next Vital Trading Levels For The Coin?
  • We’re Approaching a Recession but It’s ‘Actually a Good Thing’ – Economics Bitcoin News
  • FTX CEO Says Crypto Exchange Is Ready to Spend Billions on Acquisition Deals – Bitcoin News

Recent Comments

No comments to show.
  • New REvil Samples Indicate Ransomware Gang is Back After Months of Inactivity cyber security news
  • Avalanche Crumbles More Than 16% As Crypto Landslide Continues bitcoin news
  • Researchers Disclose 10-Year-Old Vulnerabilities in Avast and AVG Antivirus cyber security news
  • ‘It’s Hard Not to Want to Be Long Crypto’ – Featured Bitcoin News bitcoin news
  • How Poor User Experiences Lower the Market Cap for NFTs bitcoin news
  • Rarestone Capital’s Jared Polites on the State of Blockchain Marketing in 2022 bitcoin news
  • California Governor Newsom Signs Executive Order on Crypto, Blockchain, and Web3 – Regulation Bitcoin News bitcoin news
  • Central Bank of Chile Studies Issuance of a Digital Currency – Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme