THREAT OPS › Threat News › The security signal log tailing can't see: tracking npm cooldown removals with Elastic Agent
The security signal log tailing can't see: tracking npm cooldown removals with Elastic Agent
<p>npm's <code>min-release-age</code> setting tells npm to ignore any package version published less than a set number of days ago, keeping freshly compromised releases out of <code>npm install</code> during the window when they do the most damage. Getting the setting onto developer workstations is straightforward. Knowing when someone quietly deletes it is a different problem entirely, and log-ta
MITRE ATT&CK techniques
Indicators of compromise
- https://docs.npmjs.com/cli/v11/using-npm/configurl
- https://cooldowns.devurl
- registry.npmjs.orgdomain