Why Empty NPM Package Has Over 700,000 Downloads

Share post:

An NPM package with the tag “-” has had almost 720,000 downloads since its release in the npm register at the beginning of 2020.

This is because the packet is fed whenever someone makes a typo while executing npm commands.

There is only one version of the package and this version “0.0.1” contains three files, but the contents of the files have nothing groundbreaking and mainly contain skeleton code.

The obviously useless package “-” serves as a dependency for over 50 npm packages.

But it is still something to worry about. Although the package does not contain much at the moment, it may have a newer version that is more malicious.

For more information, read the original story in Bleeping Computer.

SUBSCRIBE NOW

Related articles

Microsoft reveals critical security flaw affecting Android apps

Microsoft has identified a serious vulnerability in Android apps that could allow malicious software to hijack legitimate apps...

Chinese government websites “Riddled with security flaws” say researchers

A recent study conducted by researchers from the Harbin Institute of Technology reveals significant security issues plaguing Chinese...

Cyber Security Today, May 3, 2024 – North Korea exploits weak email DMARC settings, and the latest Verizon analysis of thousands of data breaches

This episode reports on warnings about threats from China, Russia and North Korea, the hack of Dropbox Sign's infrastructure

Hashtag Trending for World Password Day, Thursday, May 2nd, 2024

Security firm Okta warns of an unprecendented password stuffing attack that is piggybacking on regular user’s mobile and...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways