Should enforce passkeys not 2FA
DuckDB NPM packages 1.3.3 and 1.29.2 compromised with malware
21–30 of 296 posts
Re: DuckDB NPM packages 1.3.3 and 1.29.2 compromised with malware
#22> According to the npm statistics, nobody has downloaded these packages before they were deprecated Is this actually accurate? Packages with weekly downloads in the hundreds of thousands, yet in the 4+ hours that the malicious versions were up for, not a single person updated any of them to the latest patch release?
DuckDB maintainer here, thanks for flagging this. Indeed the npm stats are delayed. We will know in a day or so what the actual count was. In the meantime, I've removed that statement.
Re: DuckDB NPM packages 1.3.3 and 1.29.2 compromised with malware
#23Re: DuckDB NPM packages 1.3.3 and 1.29.2 compromised with malware
#24Earlier quoted context omitted.
DuckDB maintainer here, thanks for flagging this. Indeed the npm stats are delayed. We will know in a day or so what the actual count was. In the meantime, I've removed that statement.
I think you should unpublish rather than deprecate... `npm unpublish package@version` ... It's possible within 72h. One reason is that the patched version contains -alpha... so tools like npm-check-updates would keep the 1.3.3 as the latest release for those who installed it
Re: DuckDB NPM packages 1.3.3 and 1.29.2 compromised with malware
#25So far, it seems to be a bog-standard phishing email, with not much novelty or sophistication, seems the people running the operation got very lucky with their victims though. I'm starting to think we haven't even seen the full scope of it yet, two authors confirmed as compromised, must be 10+ out there we haven't heard of yet?
The fact this is NOT the standard phishing email shows how low the bar is:
1. the text of the email reads like one you'd get from npm in the tone, format and lack of obvious spelling & grammatical errors. It pushes you to move quicker than you might normally, without triggering the typical suspicions.
2. the landing domain and website copy seem really close to legit, no obfuscated massive subdomain, no uncanny login screen, etc.
All the talk of AI disrupting tech; this is an angle where generative AI can have a massive impact in democratizing the global phishing industry. I do agree with you that there's likely many more authors who have been tricked and we haven't seen the full fallout.
Re: DuckDB NPM packages 1.3.3 and 1.29.2 compromised with malware
#26Re: DuckDB NPM packages 1.3.3 and 1.29.2 compromised with malware
#27Re: DuckDB NPM packages 1.3.3 and 1.29.2 compromised with malware
#28Comes with the territory considering that npm is defacto the number one enshittification dependency by now. But no worries - this will scale beautifully. downvotes appreciated but also happy to see one or two urls that would prove me wrong