TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Lobsters — security tag

Let's enable MFA for all Ruby gems

thoughtbot.com via MatheusRich · 6 days ago · Read original ↗

ATT&CK techniques detected

2 predictions
T1195.001Compromise Software Dependencies and Development Tools
98%
“let ' s enable mfa for all ruby gems a few weeks ago, axios, the popular http client for javascript, suffered a supply chain attack on npm. an attacker compromised the lead maintainer ’ s npm account through social engineering and published two backdoored versions that delivered …”
T1587Develop Capabilities
35%
“let ' s enable mfa for all ruby gems a few weeks ago, axios, the popular http client for javascript, suffered a supply chain attack on npm. an attacker compromised the lead maintainer ’ s npm account through social engineering and published two backdoored versions that delivered …”

Summary

Comments