3 ms·
Malicious NPM package targets prettier library
- andrewfromx 2y agowow, it ain't pretty!
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- Hackbraten 2y agoSo if I understand the article correctly, the malicious .exe file was disguised using a Unicode right-to-left override (RTLO) attack?
- 6mile 2y agoCorrect.
- beardyw 2y ago> Generally, it’s a good idea not to blindly install NPM packages. Given the nature of npm that is pretty hard to avoid.
- 6mile 2y agoTransitive dependencies, yeah, but top-level dependencies that you are installing with npm i or via your manifest file are areas that you do control and can manage.
- null_deref 2y agoVery interesting read, very impressive. With GitHub’s new feature of custom repository properties it can be so easy to implement a confirmation mechanism between a repository and an npm package, but I guess it could have implemented with other means long time ago.
- 6mile 2y agoThanks! Lots of tooling out there, but not much uptake. I mean, npm itself has better, more secure alternatives, but is still the most popular registry on the planet. Like, wtf?!