• InternetCitizen2@lemmy.world
      link
      fedilink
      English
      arrow-up
      14
      ·
      27 days ago

      Real question? Is it really isolated to npm or is there a few lessons others could take and discover their own vulnerabilities?

      • nyan@lemmy.cafe
        link
        fedilink
        English
        arrow-up
        7
        ·
        26 days ago

        Python and Ruby have both had various repo issues too.

        I’ve never heard of anything similar with Perl, but that may partly be because applications for new developers who want to join CPAN still appear to be processed by humans, with up to a couple of weeks lag. The time inefficiency plus the language being less popular probably makes it an unattractive target.

  • NOT_RICK@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    27 days ago

    Thought this was a reference to the hardcore band for a second… seeing them next month for the first time. I’m pumped! Sucks the malware is back

  • fubarx@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    26 days ago

    That is pretty evil.

    Without signing attestation (both developer and code) there will be no way to find out who was responsible and stop the propagation. This will happen again.

    Edit: there have been attempts like https://docs.npmjs.com/trusted-publishers, but that hasn’t fixed the problem.