4 ms·
I'm co-founder of Phylum (https://phylum.io https://phylum.io), the group that originally identified/reported this campaign back in June [1] and that Github ref
by louislang 3y ago
I'm co-founder of Phylum (https://phylum.io https://phylum.io), the group that originally identified/reported this campaign back in June [1] and that Github references [2] in their security alert. Happy to answer any questions about this campaign and any other supply chain attacks.
1. https://blog.phylum.io/sophisticated-ongoing-attack-discovered-on-npm/ https://blog.phylum.io/sophisticated-ongoing-attack-discover...
2. https://github.blog/2023-07-18-security-alert-social-engineering-campaign-targets-technology-industry-employees/ https://github.blog/2023-07-18-security-alert-social-enginee...
- Uptrenda 3y agoGood work on finding this. This is a scary attack.
- louislang 3y agoThanks, we report _many_ of these every day to all the ecosystems. It's wild how many malware packages get released. Doing our best to help clean up these ecosystems for everyone!
- yjftsjthsd-h 3y agoI guess a couple questions, if you don't mind: 1. Can you say how you find things like this? Just bulk scanning packages doing pattern matching heuristics? 2. I know it gets talked about every time, but I'd be interested in your perspective on how we (as an industry) could stop this kind of thing from happening. Is it as easy as blocking hooks from executing, or is there a better way forward? EDIT: Oh, just now seeing https://news.ycombinator.com/item?id=36869587 https://news.ycombinator.com/item?id=36869587 - so I'm assuming your answer is better sandboxing:)