4 ms·
Man, I never hear good security things about npm
by QuantumNoodle 4mo ago
Man, I never hear good security things about npm
- Retr0id 4mo agoThis doesn't really have anything to do with npm.
- vitamark 4mo agoanything except that it's malware installed via npm
- Retr0id 4mo agoAs you can see here, they've already switched it out for a different command, likely due to incident responders over-indexing on npm as an IOC. https://news.ycombinator.com/item?id=48503258 https://news.ycombinator.com/item?id=48503258
- notabotiswear 4mo agoFrom the Arch mailing list [0] >The result is a rather long list of ~408 packages all doing npm install atomic-lockfile something something [0] https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/message/ALAZHW5PJJUJTT5ICIHDXB6AKSICZ6MA/ https://lists.archlinux.org/archives/list/aur-general@lists....
- Retr0id 4mo agoThey could've pip installed, curl|sh'd or anything else, it's not relevant to the underlying issue.
- notabotiswear 4mo agoPerhaps there were other vectors, but npm was the one used here. And yes, this is an AUR issue, but npm being used to host and dissiminate malware is also [a chronic] one, even if separate.
- animitronix 4mo agoSo true. The JavaScript ecosystem is trash.