• A_norny_mousse@piefed.zip
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    1
    ·
    edit-2
    7 hours ago

    Thanks. The forum thread’s beginning suggests a concerted effort around adding the line npm install atomic-lockfile to repos.

    Searching for that I quickly found this: https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency and related articles.

    Then it seems to change to ‘bun’ and ‘js-digest’: bun add figures debug js-digest

    Apparently both atomic-lockfile and js-digest are upstream npm/javascript packages that have been infected with datamining malware.

    BTW, admins reported as of 12h ago it’s all cleaned up.