4 ms·
I was curious if the offending commit is still there but I didn't see anything that looked like it: https://github.com/cdnjs/cdnjs/commits/master?after=6901ec10
by uyt 5y ago
I was curious if the offending commit is still there but I didn't see anything that looked like it: https://github.com/cdnjs/cdnjs/commits/master?after=6901ec1013898b017734de9c5c4b46f668bf0919+6000&branch=master https://github.com/cdnjs/cdnjs/commits/master?after=6901ec10...
That commit log should give you a better sense of what happened if you (like me) didn't understand how cdnjs works. Apparently robocdnjs will just pull arbitrary packages and unzip and commit them into the cdnjs repo which then gets served all over the internet. Crazy!
- shoo 5y agore: the timing reported in the article > April 6, 2021 20:30 [JST] cdnjs processed the file you can see commits in the cdnjs/cdnjs git log adding an absurdly named test package from one of the maintainers to test packages containing symlinks within 24 hours after the exploit