Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. #Breaking There's an active nodejs supply chain attack going around.

#Breaking There's an active nodejs supply chain attack going around.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
breakingnodejscybersecurityawsgithub
21 Indlæg 1 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • nullagent@partyon.xyzN nullagent@partyon.xyz

    And to be clear this is NOT an all clear just yet. Why?

    1. There remain known malicious packages STILL available for download on NPM (and I can see evidence of active downloads)

    https://partyon.xyz/@nullagent/115607663085751105

    2. Infected computers and servers are STILL posting stolen PII to public githubs for the world to see. GitHub has just gotten a tad faster at taking them down.

    https://partyon.xyz/@nullagent/115607844583101135

    So this is a smoldering fire still and we need to stay vigilant.

    #Sha1Hulud #WalkWithoutRhythm

    nullagent@partyon.xyzN This user is from outside of this forum
    nullagent@partyon.xyzN This user is from outside of this forum
    nullagent@partyon.xyz
    wrote sidst redigeret af
    #21

    These sorts of NPM worms have been around for a LONG time.

    It's typically due a common practice of low 2fa opt-in on NPM accounts.

    So be sure to setup NPM 2FA if you're a package maintainer do that asap!

    A lesser known NPM capability is that you can disable install time scripts. This may break some packages but its worth a try to see if your projects can work with out any install scripts. 👇🏿

    https://blog.npmjs.org/post/141702881055/package-install-scripts-vulnerability

    #GitHub #NPM #Microsoft #Sha1Hulud #nodejs #javascript

    1 Reply Last reply
    1
    0
    • pelle@veganism.socialP pelle@veganism.social shared this topic
    Svar
    • Svar som emne
    Login for at svare
    • Ældste til nyeste
    • Nyeste til ældste
    • Most Votes


    • Log ind

    • Har du ikke en konto? Tilmeld

    • Login or register to search.
    Powered by NodeBB Contributors
    Graciously hosted by data.coop
    • First post
      Last post
    0
    • Hjem
    • Seneste
    • Etiketter
    • Populære
    • Verden
    • Bruger
    • Grupper