# The npm attack that turned provenance attestations into camouflage

> Quelle: The New Stack — https://thenewstack.io/npm-supply-chain-worm-attack/

## Maßnahmen

- [ ] Betroffenheit im eigenen Stack prüfen: Versionen/Komponenten abgleichen.
- [ ] Originalquelle / Hersteller-Advisory lesen: https://thenewstack.io/npm-supply-chain-worm-attack/
- [ ] Verfügbaren Patch oder Workaround einspielen und dokumentieren.
