5 ms·
It's by far the most popular method of malicious payload execution for these kinds of attacks. It's easy to write, definitely executed (if not for the settings
by dubbel 6y ago
It's by far the most popular method of malicious payload execution for these kinds of attacks.
It's easy to write, definitely executed (if not for the settings suggested by the blog posts), doesn't depend on the usage of the library by the victim, and you don't really need to know anything about the setup the victim has.
You are right in that it's not the patch that fixes the entire problem, but that is rarely the case in security.
Source: earlier this year i analysed every package dependency compromise between 2006-2017.
https://www.haukeluebbers.de/blog/2020-01-timeline-of-package-dependency-compromises/ https://www.haukeluebbers.de/blog/2020-01-timeline-of-packag...
You can see that the most common method for npm, Rubygems and pypi is something like "Method: executed by install hook"