3 ms·
> But how would you manage to create a malicious library and have it approved by cdnjs? That's the part of the exploit that sounds the hardest, and I don't see
by MattIPv4 5y ago
> But how would you manage to create a malicious library and have it approved by cdnjs? That's the part of the exploit that sounds the hardest, and I don't see a reasonable way to go about it.
1. Hijack an existing library to publish the malicious version
2. or, Have us approve what looks like a legitimate library, which later publishes a malicious version
- teddyh 5y ago> 1. Hijack an existing library Hijack or buy outright an existing library. IIRC, there have been many such instances where existing projects have been sold for large sums to questionable parties.