top | item 16087905

(no title)

seldo | 8 years ago

Hi folks, npm COO here. This was an operational issue that we worked to correct. All packages are now restored:

https://status.npmjs.org/incidents/41zfb8qpvrdj

discuss

order

yashap|8 years ago

Were any of the deleted packages temporarily hijacked? It seems strongly like this was the case. If so, please confirm immediately so people who installed packages during this time can start scanning for malware.

Even if the answer is “yes, 1+ packages were hijacked by not-the-original author, but we’re still investigating if there was malware”, tell people immediately. Don’t wait a few days for your investigation and post mortem if it’s possible that some users’ systems have already been compromised.

electric_sheep|8 years ago

I would also hope for and expect this to be communicated ASAP from the NPM org to its users.

@seldo, I understand that you don't want to disseminate misleading info, but an abundance of caution seems warranted in this case as my understanding of the incident lines up with what @yashap has said. If we're wrong, straighten us out --- if we're not, please sound an advisory, because this is major.

f4rker|8 years ago

[deleted]

nnutter|8 years ago

Seems like you should have froze publishing instead of saying, "Please do not attempt to republish packages, as this will hinder our progress in restoring them." Especially, to prevent, even temporary, hijacking.

thsowers|8 years ago

Any chance of a technical write-up so that we can all learn from whatever happened?

seldo|8 years ago

Absofuckinglutely. It's being done as we speak.

xwvvvvwx|8 years ago

What was the root cause of the issue?

chrisfosterelli|8 years ago

Yes I'd be very curious to see a debrief on what the technical cause was. Thanks to the npm team for a quick weekend fix, at any rate!

drdrey|8 years ago

Or rather: what were the contributing factors of the issue?