Embedded malware in RC (NPM package)
github.com
Embedded malware in RC (NPM package)
1–10 of 117 posts
Re: Embedded malware in RC (NPM package)
#2Re: Embedded malware in RC (NPM package)
#3Re: Embedded malware in RC (NPM package)
#4Note how the referenced Virustotal result has 40+ detections [1]. I'm still wondering why info like this isn't used by Pypi and NPM. Chocolatey has Virustotal integration for all releases.
And it's not like Virustotal is the only option, there is Cape [2] for dynamic execution, Metadefender, and Intezer Analyze just to name a few.
Really confusing for such a vital supply chain component to be this easily abused.
One of the highlights is when someone recently used NPM to spread ransomware via a fake Roblox API package.[3]
[1] https://www.virustotal.com/gui/file/26451f7f6fe297adf6738295...
[2] https://github.com/kevoreilly/CAPEv2
[3] https://www.reddit.com/r/programming/comments/qgz0em/fake_np...
Re: Embedded malware in RC (NPM package)
#5Why the fuck do all these leftpad is-even hello-world tic-tac-toe packages have millions of downloads?
Re: Embedded malware in RC (NPM package)
#6I checked the readme of both those packages and I can't for the life of me understand why would anyone use either of them. Why the fuck do all these leftpad is-even hello-world tic-tac-toe packages have millions of downloads?
And perhaps some faked download numbers to lend an air of authenticity.
Re: Embedded malware in RC (NPM package)
#7I checked the readme of both those packages and I can't for the life of me understand why would anyone use either of them. Why the fuck do all these leftpad is-even hello-world tic-tac-toe packages have millions of downloads?
Chained dependencies? If you can fool one popular package to depend on you, you ride their coattails. And perhaps some faked download numbers to lend an air of authenticity.
Re: Embedded malware in RC (NPM package)
#8And yet again, twice in a row this time. Note how the referenced Virustotal result has 40+ detections [1]. I'm still wondering why info like this isn't used by Pypi and NPM. Chocolatey has Virustotal integration for all releases. And it's not like Virustotal is the only option, there is Cape [2] for dynamic execution, Metadefender, and Intezer Analyze just to name a few. Really confusing for such a vital supply chain…
Re: Embedded malware in RC (NPM package)
#9I checked the readme of both those packages and I can't for the life of me understand why would anyone use either of them. Why the fuck do all these leftpad is-even hello-world tic-tac-toe packages have millions of downloads?
Re: Embedded malware in RC (NPM package)
#10RFC: https://github.com/npm/rfcs/pull/488
Related HN post: https://news.ycombinator.com/item?id=29122473