5 ms·
From sindresorhus: You can run the following to check if you have the malware in your dependency tree: `rg -u --max-columns=80 _0x112fa8` Requires ripgrep:
by joaomoreno 1y ago
From sindresorhus:
You can run the following to check if you have the malware in your dependency tree:
`rg -u --max-columns=80 _0x112fa8`
Requires ripgrep:
`brew install rg`
https://github.com/chalk/chalk/issues/656#issuecomment-3266880534 https://github.com/chalk/chalk/issues/656#issuecomment-32668...
- koolba 1y agoTry the same recursive grep on ~/.npm to see if you have it cached too. Not just the latest in the current project.
- tripplyons 1y agoHaven't installed any modules today, but I ran these commands to clear caches for npm and pnpm just to be safe. npm cache clean --force pnpm cache delete
- PokestarFan 1y agoYou probably want to check before you clear cache
- cgijoe 1y agoSorry, I am unfamiliar with ripgrep. Is this simply scanning for the string `_0x112fa8`? Could we do the same thing with normal grep -r?
- skrebbel 1y agoyes. ripgrep just does it faster, is all.
- hinkley 1y agoMake it work, make it right, make it fast. For security checks, the first 2 out of 3 is just fine.
- Aeolun 1y agoSure, but if you can get the last for free, why not?
- nothrabannosir 1y agoBut also respects .gitignore by default so I’m not sure you want to use ripgrep to scan your node_modules
- Fishkins 1y agoFor others who didn't know, the -u flag in the OP's command makes it so ripgrep _will_ search files even if they're gitignored
- postalcoder 1y ago-u searches through ignored files -uu searches through ignored and hidden files (eg dotfiles) -uuu searches through ignored, hidden, and binary files (ie everything)
- AkshatJ27 1y agoIsn't the intended behaviour of original comment checking the node_modules folder for the "infected" string.
- EasyMark 1y ago[flagged]
- naikrovek 1y agoI feel like you were trying to help here, but anyone can do this for themselves. Providing information in this way sort of indicates that you don't believe that the person you're replying to can do it on their own, and for that reason it's considered rude.
- skygazer 1y agoAlso, HN hates machine generated replies, especially the lengthy and overly verbose slop variety -- I think that probably eclipsed any perceived rudeness.
- tbossanova 1y agoI see what you mean, but I actually think there is a place for copy/pasting AI responses. I think of it as a kind of cache, surely a HN comment being served to n users means less resources used and faster access than if all n did their own AI query. But then of course you don’t get exactly your preference e.g. you might prefer a terser response than what is pasted here. Interesting to see how the etiquette around this plays out over time.
- vasco 1y agoIf you ever wanted to share an AI response, you probably should share your prompt, not the response. But likely you should not share anything, for the reasons already explained. Your argument about saving energy makes zero sense if you have any understanding of orders of magnitude but I won't share what AI says about it.
- tbossanova 1y agoIronically you are being incredibly rude trying to support an argument that posting AI responses is rude. I guess we can conclude you know nothing about anything.
- deleted 1y ago[deleted]
- timsh 1y agoIf it produces no output, does that mean that there's no code that could act in the future? I first acted out of nerves and deleted the whole node-modules and package.lock in a couple of freshly opened Astro projects, curious if I should considered my web surfing to still be potentially malicious
- nosefurhairdo 1y agoThe malware introduced here is a crypto address swapper. It's possible that even after deleting node_modules that some malicious code could persist in a browser cache. If you have crypto wallets on the potentially compromised machine, or intend to transfer crypto via some web client, proceed with caution.
- aerodynamic_ 1y agoconvenience script that checks through package.json dependency tree + a couple malicious binary patterns: https://gist.github.com/edgarpavlovsky/695b896445c19b6f66f141696f596059 https://gist.github.com/edgarpavlovsky/695b896445c19b6f66f14...
- NamlchakKhandro 1y agodoesn't work for monorepos
- yifanl 1y agoAsking people to run random install scripts just feels very out of place given the context.
- hunter2_ 1y agoI would agree if this were one of those `curl | sh` scenarios, but don't we consider things like `brew` to be sufficiently low-risk, akin to `apt`, `dnf`, and the like?
- tripplyons 1y agoAnyone can upload an NPM package without much review. For Homebrew, you at least have to submit a pull request.
- what 1y agoHomebrew has been compromised before. To think it’s immune is a bit naive.
- n8m8 1y agoAgreed that it's a bit funny given the context and no community-managed package manager should be 100% trusted. That said, I think rg is pretty well known to linux daily-drivers and they just wanted to share something quickly for powerusers who want to check their workspaces quickly. Probably better to just instruct n00bs to use grep than install a whole cli tool for searching Come to think of it, I wonder if a 2-phase attack could be planned by an attacker in the future: Inject malware into a package, flood guidance with instructions to install another popular tool that you also recently compromised... lol
- tripplyons 1y agoI'm not saying its immune. I'm saying that NPM doesn't have as many protections, making NPM an easier target.
- n8m8 1y ago
- airtonix 1y ago[dead]
- dabockster 1y agoHere's something I generated in my coding AI for Powershell: `Get-ChildItem -Recurse | Select-String -Pattern '_0x112fa8' | ForEach-Object { $_.Line.Substring(0, [Math]::Min(80, $_.Line.Length)) }` Breakdown of the Command: - Get-ChildItem -Recurse: This command retrieves all files in the current directory and its subdirectories. - Select-String -Pattern '_0x112fa8': This searches for the specified pattern in the files. - ForEach-Object { ... }: This processes each match found. - Substring(0, [Math]::Min(80, $_.Line.Length)): This limits the output to a maximum of 80 characters per line. --- Hopefully this should work for Windows devs out there. If not, reply and I'll try to modify it.
- metaltyphoon 1y agoOr you can just install ripgrep on windows too and have it check much faster ;)