(no title)
cddotdotslash | 5 months ago
Aikido says: > We were alerted to a large-scale attack against npm...
Socket says: > Socket.dev found compromised various CrowdStrike npm packages...
Ox says: > Attackers slipped malicious code into new releases...
Safety says: > The Safety research team has identified an attack on the NPM ecosystem...
Phoenix says: > Another supply chain and NPM maintainer compromised...
Semgrep says: > We are aware of a number of compromised npm packages
advocatemack|5 months ago
sauercrowd|5 months ago
jamesberthoty|5 months ago
And then vendors from Socket, Aikido, and Step all seem to have detected it via their upstream malware detection feeds - Socket and Aikido do AI code analysis, and Step does eBPF monitoring of build pipelines. I think this was widespread enough it was noticed by several people.
m4r71n|5 months ago
progbits|5 months ago
augzodia|5 months ago
codazoda|5 months ago
https://github.com/scttcper/tinycolor/issues/256
unknown|5 months ago
[deleted]
Onavo|5 months ago