This is how a carefully hidden backdoor in fake AWS files escaped the attention of the general public
Researchers have determined that two fake AWS packages, downloaded hundreds of times from the open source NPM JavaScript repository, contained carefully hidden code that, when executed, allowed access to developers’ computers. The packages—img-aws-s3-object-multipart-copy And legacyaws-s3-object-multipart-copy— were attempts to impersonate aws-s3-object-multipart-copy, a legitimate JavaScript library for copying files using Amazon’s S3 cloud service. The fake files … Read more