Skip to main content
Top10Grid
#8

Open source package with 1 million monthly downloads stole user credentials

An open-source package downloaded a million times per month was caught stealing user credentials, a stark reminder that trust in shared code is a fragile, dangerous gift. The package, a popular npm utility, exfiltrated login data via a hidden HTTPS connection, harvesting 1.2 million tokens over six months before discovery. The incident led to a 40% drop in the package's downloads within 24 hours.

Share:

Photos (1)

Open source package with 1 million monthly downloads stole user credentials

Comments on "Open source package with 1 million monthly downloads stole user credentials"

Have a take on this ranking?

Comments are how the argument actually happens here. Posting one needs a free account — it takes about a minute.

No comments yet.

The first comment sets the terms of the argument.