Another day of vaguely pointing at Javascript when asked where the circus is.
post
Interestingly, developers in ecosystems like Go, Rust, and those utilizing native Web APIs—where robust standard libraries drastically reduce reliance on third-party code and strict cryptographic verification is built into the core toolchain
Does NPM really not do cryptographic verification or is this part of the joke? I always assumed the attacks were due to a compromised key or something, but this is implying you can just push whatever you want to an NPM package if you have the author's login?
It's funny that we've had SLSA4-compliant package managers for 25 years, but we leave juniors un-mentored and this is what they build as they self-teach ... over and over and over.
Hilarious idea brought down by the AI slop thumbnail. The vulneráéilíties on that screen sure look OOTΓKAL.
ai! slop!!
oh, and the text is pristine, the misinformation nexus is here!! fsm help us all
all 15 comments