Hacker News
new
past
comments
ask
show
jobs
points
by
mkayokay
5 hours ago
|
comments
by
jeroenhd
5 hours ago
|
next
[-]
The attacker used at least three Node dependencies in the attack, just checking for atomic-lockfile is not enough. The names js-digest and lockfile-js were also used, and at some point the attacker switched to bun instead of npm.
reply
by
DavideNL
5 hours ago
|
prev
|
next
[-]
Also see:
https://github.com/lenucksi/aur-malware-check
reply
by
stefan_
4 hours ago
|
prev
|
[-]
I love that even when trying to put malware into Arch Linux AUR, the malware is still distributed through NPM. Legendary platform.
reply