3 ms·
In July, packages were loading malicious DLLs (on Windows targets) [1]. It doesn't appear Lavamoat would help in that scenario. Is that right? If so, how do you
by withinrafael 1y ago
In July, packages were loading malicious DLLs (on Windows targets) [1]. It doesn't appear Lavamoat would help in that scenario. Is that right? If so, how do you mitigate this? Run everything in a container?
[1] https://www.crowdstrike.com/en-us/blog/crowdstrike-falcon-prevents-npm-package-supply-chain-attacks/ https://www.crowdstrike.com/en-us/blog/crowdstrike-falcon-pr...
- mike-cardwell 1y agohttps://gitlab.com/grepular/safernode https://gitlab.com/grepular/safernode
- withinrafael 1y agoThanks will check it out!
- naugtur 1y ago1. Control lifecycle scripts with @lavamoat/allow-scripts 2. Do local dev with https://github.com/lavamoat/kipuka https://github.com/lavamoat/kipuka installed (I'm working on it) 3. If you don't permit the APIs used for loading DLLs they won't load themselves, so runtime protections are valid too. But I recall the DLLs were loaded in lifecycle script.
- withinrafael 1y agoThanks will check both out!