all 13 comments

sorted by: hot top controversial new old
[–] 46 points 10 months ago* (last edited 10 months ago) (5 children)

"No Way To Prevent This" Says Only Package Manager Where This Regularly Happens*

*This is a joke about gun violence.

  • source
  • hideshow 5 child comments
  • [–] 15 points 10 months ago (4 children)

    Real question? Is it really isolated to npm or is there a few lessons others could take and discover their own vulnerabilities?

  • source
  • parent
  • hideshow 4 child comments
  • [–] 12 points 10 months ago (3 children)

    It happens in python pip too.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 5 points 10 months ago (2 children)

    Arch checking in. It may happen less. But it still does.

  • source
  • parent
  • hideshow 2 child comments
  • [+] 18 points 10 months ago* (last edited 7 months ago) (1 child)
    [–] 4 points 10 months ago (2 children)

    Thought this was a reference to the hardcore band for a second… seeing them next month for the first time. I’m pumped! Sucks the malware is back

  • source
  • hideshow 2 child comments
  • [–] 3 points 10 months ago

    I avoid NPM like the plague.

    I feel like I'm better off for it.

  • source
  • [–] 2 points 10 months ago* (last edited 10 months ago)

    That is pretty evil.

    Without signing attestation (both developer and code) there will be no way to find out who was responsible and stop the propagation. This will happen again.

    Edit: there have been attempts like https://docs.npmjs.com/trusted-publishers, but that hasn't fixed the problem.

  • source