{"version":"1.0","type":"rich","provider_name":"techandbusiness.org","provider_url":"https://techandbusiness.org","title":"Compromised npm package targets developer credentials and remote access","author_name":"techandbusiness.org · Cybersecurity","thumbnail_url":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgR_DE5ORKWCpLgZgXBuH-MFmuqfxFNnkGQxremc0ffY4dopMHnx-2HvgZTMh48BvVr8k22lGaM__jTS83DuXnLpF4NC9u4bsQF-8_K34gZU0kJS_-10pUSL7WNxecJG0pCiHyNFiqxXEqWP7NqUK2-uvwzo8-ETqwZkPWdNOjhNn5S1Y0uFQX2HGBE5_5J/s1700-nu-rw-lo-l85-e365/t-day.jpg","width":600,"height":400,"html":"<blockquote class=\"tb-newswire-embed\" style=\"max-width:600px;border-left:3px solid #22d3ee;padding:12px 16px;margin:0;font-family:-apple-system,system-ui,sans-serif;background:#09090b;border-radius:0 8px 8px 0;\">\n      <p style=\"margin:0 0 8px;font-size:10px;font-weight:600;letter-spacing:0.1em;color:#71717a;\">techandbusiness.org · Cybersecurity</p>\n      <p style=\"margin:0 0 8px;font-size:18px;font-weight:700;line-height:1.3;color:#fff;\"><a href=\"https://techandbusiness.org/newswire/cleu45_Bi9fmzQ3SiFhclh\" style=\"color:#fff;text-decoration:none;\">Compromised npm package targets developer credentials and remote access</a></p>\n      <p style=\"margin:0;font-size:14px;color:#a1a1aa;line-height:1.5;\">StepSecurity identified a hidden payload in version 5.8.3 of the npm package @subql/common that collects credentials and supports remote shell access. The code runs during installation and when the pa...</p>\n    </blockquote>"}