(no title)
mgiladi | 11 months ago
1. The maintainers could have used PRevent to immediately alert and block any PR containing malicious code, or easily configured it for detection in case of a direct push: https://github.com/apiiro/PRevent
2. Users could have used our malicious code detection ruleset to immediately detect and block it when scanning updates in all relevant CI/CD stages: https://github.com/apiiro/malicious-code-ruleset
3. For a better understanding of the detection, the malicious code falls precisely into the patterns presented in our research: https://apiiro.com/blog/guard-your-codebase-practical-steps-...
klysm|11 months ago
There is no way this would’ve prevented anything.
mgiladi|11 months ago
Add behavioral detection, and you get a strong layer of defense, even if attackers know about it. You still want defense in depth as always, of course.