Close Menu
    Main Menu
    • Home
    • News
    • Tech
    • Robotics
    • ML & Research
    • AI
    • Digital Transformation
    • AI Ethics & Regulation
    • Thought Leadership in AI

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Safe AI brokers with Coverage in Amazon Bedrock AgentCore

    March 16, 2026

    International Authorities Take Down 45,000 Malicious IPs Utilized in Ransomware Campaigns

    March 15, 2026

    The phone is 150 years outdated. It’s nonetheless altering every little thing.

    March 15, 2026
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Home»AI Ethics & Regulation»Malicious packages in npm evade dependency detection by way of invisible URL hyperlinks: Report
    AI Ethics & Regulation

    Malicious packages in npm evade dependency detection by way of invisible URL hyperlinks: Report

    Declan MurphyBy Declan MurphyOctober 31, 2025No Comments1 Min Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Malicious packages in npm evade dependency detection by way of invisible URL hyperlinks: Report
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link



    Sooner or later, npm management both found this marketing campaign by itself or was alerted by different researchers, as a result of in August, 21 packages had been faraway from the repository. Nevertheless, after September, 80 further packages had been uploaded. All, Koi Safety believes, had been clearly managed by the identical individual.

    ‘Disastrous’ flaw in npm

    This can be a “disastrous” systemic design flaw in npm’s dependency administration performance, Tanya Janca, head of Canadian safe coding coaching agency She Hacks Purple Consulting, informed CSO. The dearth of validation for dependency URLs bypasses the belief boundary for the Node.js software program provide chain, she mentioned.

    Few programming languages permit dependencies to be specified through URLs, and even most of those who do have package deal managers that block this characteristic as a result of safety issues, she mentioned. As an example, she identified, it’s allowed in Python, however the open supply Python Bundle Index repository of packages (PyPI) blocks this performance.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Declan Murphy
    • Website

    Related Posts

    International Authorities Take Down 45,000 Malicious IPs Utilized in Ransomware Campaigns

    March 15, 2026

    Cyber criminals too are working from residence… your private home

    March 15, 2026

    Iran-Linked Hacktivists Declare Harmful Cyberattack on Medtech Agency Stryker

    March 15, 2026
    Top Posts

    Evaluating the Finest AI Video Mills for Social Media

    April 18, 2025

    Utilizing AI To Repair The Innovation Drawback: The Three Step Resolution

    April 18, 2025

    Midjourney V7: Quicker, smarter, extra reasonable

    April 18, 2025

    Meta resumes AI coaching utilizing EU person knowledge

    April 18, 2025
    Don't Miss

    Safe AI brokers with Coverage in Amazon Bedrock AgentCore

    By Oliver ChambersMarch 16, 2026

    Deploying AI brokers safely in regulated industries is difficult. With out correct boundaries, brokers that…

    International Authorities Take Down 45,000 Malicious IPs Utilized in Ransomware Campaigns

    March 15, 2026

    The phone is 150 years outdated. It’s nonetheless altering every little thing.

    March 15, 2026

    Vulnerability For Leaders Is Not The Similar As It Is For Everybody Else

    March 15, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    UK Tech Insider
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms Of Service
    • Our Authors
    © 2026 UK Tech Insider. All rights reserved by UK Tech Insider.

    Type above and press Enter to search. Press Esc to cancel.