unreachable.cloud
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
cyrano@piefed.social to Technology@lemmy.worldEnglish · 1 day ago

Shai-Hulud Returns: Over 300 NPM Packages Infected

helixguard.ai

external-link
message-square
14
fedilink
75
external-link

Shai-Hulud Returns: Over 300 NPM Packages Infected

helixguard.ai

cyrano@piefed.social to Technology@lemmy.worldEnglish · 1 day ago
message-square
14
fedilink
HelixGuard
helixguard.ai
external-link
Supply chain security, vulnerability intelligence, and malware detection.

cross-posted from: https://lemmy.bestiver.se/post/758000

Comments

alert-triangle
You must log in or register to comment.
  • fubarx@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    7 hours ago

    That is pretty evil.

    Without signing attestation (both developer and code) there will be no way to find out who was responsible and stop the propagation. This will happen again.

    Edit: there have been attempts like https://docs.npmjs.com/trusted-publishers, but that hasn’t fixed the problem.

  • camdog2000@ttrpg.network
    link
    fedilink
    English
    arrow-up
    3
    ·
    9 hours ago

    I avoid NPM like the plague.

    I feel like I’m better off for it.

  • earthworm@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    47
    arrow-down
    2
    ·
    edit-2
    1 day ago

    “No Way To Prevent This” Says Only Package Manager Where This Regularly Happens*

    *

    This is a joke about gun violence.

    • InternetCitizen2@lemmy.world
      link
      fedilink
      English
      arrow-up
      14
      ·
      1 day ago

      Real question? Is it really isolated to npm or is there a few lessons others could take and discover their own vulnerabilities?

      • nyan@lemmy.cafe
        link
        fedilink
        English
        arrow-up
        8
        ·
        23 hours ago

        Python and Ruby have both had various repo issues too.

        I’ve never heard of anything similar with Perl, but that may partly be because applications for new developers who want to join CPAN still appear to be processed by humans, with up to a couple of weeks lag. The time inefficiency plus the language being less popular probably makes it an unattractive target.

      • frongt@lemmy.zip
        link
        fedilink
        English
        arrow-up
        11
        ·
        1 day ago

        It happens in python pip too.

        • Eldritch@piefed.world
          link
          fedilink
          English
          arrow-up
          5
          ·
          1 day ago

          Arch checking in. It may happen less. But it still does.

          • orclev@lemmy.world
            link
            fedilink
            English
            arrow-up
            7
            ·
            1 day ago

            To be fair to Arch, the AUR was always advertised as a caveat emptor type thing. It never really claimed to be secure in the first place.

            • Eldritch@piefed.world
              link
              fedilink
              English
              arrow-up
              2
              ·
              8 hours ago

              That is fair.

  • _cryptagion [he/him]@anarchist.nexus
    link
    fedilink
    English
    arrow-up
    20
    arrow-down
    1
    ·
    1 day ago

    “Bless the Maker and His water.
    Bless the coming and going of Him.
    May His passage cleanse the world.
    May He keep the world for His people.”

    • InternetCitizen2@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      3
      ·
      1 day ago

      Alt text

  • NOT_RICK@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    1 day ago

    Thought this was a reference to the hardcore band for a second… seeing them next month for the first time. I’m pumped! Sucks the malware is back

    • Schmuppes@lemmy.today
      link
      fedilink
      English
      arrow-up
      6
      ·
      1 day ago

      It’s surely a reference to the Dune novels.

      • NOT_RICK@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        23 hours ago

        Yup

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @[email protected]
  • @[email protected]
  • @[email protected]
  • @[email protected]
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 2.89K users / day
  • 8.29K users / week
  • 14.5K users / month
  • 32.4K users / 6 months
  • 1 local subscriber
  • 77.1K subscribers
  • 14.4K Posts
  • 544K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemmy.world
  • Technopagan@lemmy.world
  • L4sBot@lemmy.world
  • L3s@hackingne.ws
  • L4s@hackingne.ws
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org