3 ms·
The phishing email comes across a bit too amateur. Specifically the inclusion of: "we kindly ask that you complete this update your earliest convenience". The
by sflanagain 1y ago
The phishing email comes across a bit too amateur. Specifically the inclusion of:
"we kindly ask that you complete this update your earliest convenience".
The email was included here: https://cdn.prod.website-files.com/642adcaf364024654c71df23/68bf028d86e3642f1268253f_050c42b9.png https://cdn.prod.website-files.com/642adcaf364024654c71df23/...
From this article: https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised https://www.aikido.dev/blog/npm-debug-and-chalk-packages-com...
- huflungdung 1y ago[dead]
- rurban 1y agoVery amateur. Who would fall that, really? I can only suspect npm people who are used to unprofessional repo hosting practices. Such a Two Factor Authentication update request would have needed a blog post first, to announce such a fishy request.