Malicious crossenv package on npm
twitter.com
Malicious crossenv package on npm
1–10 of 237 posts
Re: Malicious crossenv package on npm
#2This should be signal boosted as hard as it can be managed, because this is rough stuff.
Re: Malicious crossenv package on npm
#3This is important. It looks like the organization is submerging; they've deleted their NPM account and the package and emptied their GitHub repo. This should be signal boosted as hard as it can be managed, because this is rough stuff.
Re: Malicious crossenv package on npm
#4The only thing you can do is be careful and listen for projects like node security.
Re: Malicious crossenv package on npm
#5This is important. It looks like the organization is submerging; they've deleted their NPM account and the package and emptied their GitHub repo. This should be signal boosted as hard as it can be managed, because this is rough stuff.
What can be done to help sort problems like this?
Re: Malicious crossenv package on npm
#6Re: Malicious crossenv package on npm
#7Re: Malicious crossenv package on npm
#8since the user appears to have been nuked...
Re: Malicious crossenv package on npm
#9This is serious stuff and we will definitely see more of it in the future! As there are more and more node.js developers, it will be more profitable to run a scam like this and you only need to hijack one page that has a lot of dependencies, one package that is for example used by `express` to get access to a lot of users. The only thing you can do is be careful and listen for projects like node security.