3 ms·
I can't wait for npm/github to do literally anything at all to mitigate these attacks. Literally anything. Have we considered a basic WAF-style block on some po
by 827a 5mo ago
I can't wait for npm/github to do literally anything at all to mitigate these attacks. Literally anything. Have we considered a basic WAF-style block on some postinstall script strings? LLM-assisted code scanning on publish? Is there anyone home? No I suspect not.
- pier25 5mo agoThird parties can detect compromised packages. It’s ridiculous Microsoft doesn’t.
- lyu07282 5mo agoThey can and do indeed detect those attacks, it's just from Microsoft's POV a feature of Microsoft Defender (on Windows and Cloud) they sell: https://www.microsoft.com/en-us/security/blog/2025/12/09/shai-hulud-2-0-guidance-for-detecting-investigating-and-defending-against-the-supply-chain-attack/ https://www.microsoft.com/en-us/security/blog/2025/12/09/sha... https://azure.microsoft.com/en-us/pricing/details/defender-for-cloud/ https://azure.microsoft.com/en-us/pricing/details/defender-f... So this is presumably why they will never address this in npm itself.
- grim_io 5mo agoMaybe they should prove their shit works first. What a wonderful marketing opportunity! Leave it to Microsoft to blindly ignore it.
- lyu07282 5mo agoNo look at the article of this post, it's by SafeDep they are in the same business as Microsoft with their Defender product line. They both publish near identical post mortems with subtle hints at how their product would've defended you against the attack. Why should Microsoft fix the cause instead of selling the cure to each business individually?
- grim_io 5mo agoIs the complete loss of trust in the platform they want to profit off a better alternative?
- lyu07282 5mo agoIt's essential infrastructure there is only one node package manager. I'm not saying it's a good thing, I just describe the systemic reason why it's broken, because that's usually never expressed but its important.
- mannanj 5mo agoWhy would a corporate company actually demonstrate responsibility and ethicality in its use of the open source commons from which it extracts every last penny and dollar? Edit: a more suitable strategy is to do the minimal necessary actions for appearance purposes only, as its how to focus and optimize on its interest for revenue for its shareholders.
- dawnerd 5mo agoThey will once they figure out how to charge for it (which GitHub is trying according to the security scanning banner they keep showing me).
- WorldMaker 5mo agoIt still seems wild that npm hasn't gone allowlist-only for pre- and post-install scripts like every other JS package manager (yarn, pnpm, Deno, Bun). Obviously it would be a breaking change that might wreck some developers' day for a little while until that allowlist is built, but it would go a long way to eliminate some of the biggest vectors for these attacks.
- zahlman 5mo ago... Deno and Bun manage packages? I thought they were just runtimes.
- WorldMaker 5mo agoBun started out with npm compatibility as a key requirement, so has a very npm-like package manager from the beginning. Deno at first tried to focus only on web-like/browser-like package management with a focus on full URLs ("https://mypackage.example.com/v2/mypackage.js https://mypackage.example.com/v2/mypackage.js") and importmaps (a JSON file mapping "mypackage" to a URL such as the previous example) and package/file caching over installing. Deno 2 made Node-compatibility a higher priority (partly because of Bun's competition, partly because of complaints that Deno was hard to migrate to piecemeal from existing Node codebases) and one of those initiatives was a more npm-compatible package manager out of the box (that can also speak Node package.json and manage a node_modules directory), even as Deno still encourages for greenfield projects the URL/importmap/caching approach (with the expansion that it also understands `npm:` pseudo-URLs, `jsr:` pseudo-URLs [an alternative package registry with a stronger focus on ESM and Typescript types], and `node:` pseudo-URLs [emulated node internals], beyond just browser-safe `http:` and `https:` URLs).