all 13 comments

sorted by: hot top controversial new old
[–] 46 points 9 months ago* (last edited 9 months ago) (1 child)

"No Way To Prevent This" Says Only Package Manager Where This Regularly Happens*

*This is a joke about gun violence.

  • source
  • hideshow 2 child comments
  • [–] 15 points 9 months ago (1 child)

    Real question? Is it really isolated to npm or is there a few lessons others could take and discover their own vulnerabilities?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 12 points 9 months ago (1 child)

    It happens in python pip too.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 5 points 9 months ago (1 child)

    Arch checking in. It may happen less. But it still does.

  • source
  • parent
  • hideshow 2 child comments
  • [+] 18 points 9 months ago* (last edited 6 months ago) (1 child)
    [–] 4 points 9 months ago (1 child)

    Thought this was a reference to the hardcore band for a second… seeing them next month for the first time. I’m pumped! Sucks the malware is back

  • source
  • hideshow 2 child comments
  • [–] 3 points 9 months ago

    I avoid NPM like the plague.

    I feel like I'm better off for it.

  • source
  • [–] 2 points 9 months ago* (last edited 9 months ago)

    That is pretty evil.

    Without signing attestation (both developer and code) there will be no way to find out who was responsible and stop the propagation. This will happen again.

    Edit: there have been attempts like https://docs.npmjs.com/trusted-publishers, but that hasn't fixed the problem.

  • source