Malicious npm packages detected across Red Hat Cloud Services
1–10 of 494 posts
Re: Malicious npm packages detected across Red Hat Cloud Services
#2Re: Malicious npm packages detected across Red Hat Cloud Services
#3Edit: some people don't understand that it's a defence to https://en.wikipedia.org/wiki/%27No_Way_to_Prevent_This,%27_...
Re: Malicious npm packages detected across Red Hat Cloud Services
#4Re: Malicious npm packages detected across Red Hat Cloud Services
#5https://gist.github.com/mcollina/b294a6c39ee700d24073c0e5a4e...
Re: Malicious npm packages detected across Red Hat Cloud Services
#6Updated:
1. All exploitation techniques used since May 2025: https://npm-supply-chain-attack-techniques.pagey.site/
2. All attacks that happened since May 2025: https://npm-supply-chain-attacks-25-26.pagey.site/
Re: Malicious npm packages detected across Red Hat Cloud Services
#7Our company uses yarn 4 which has an option to prevent you from installing an npm package for the first number of days of its release. Most of these seem to be caught within that timeframe (1-3 days). https://gist.github.com/mcollina/b294a6c39ee700d24073c0e5a4e...
Re: Malicious npm packages detected across Red Hat Cloud Services
#8Re: Malicious npm packages detected across Red Hat Cloud Services
#9Our company uses yarn 4 which has an option to prevent you from installing an npm package for the first number of days of its release. Most of these seem to be caught within that timeframe (1-3 days). https://gist.github.com/mcollina/b294a6c39ee700d24073c0e5a4e...
Re: Malicious npm packages detected across Red Hat Cloud Services
#10'No Way to Prevent This,' Says Only package manager Where This Regularly Happens Edit: some people don't understand that it's a defence to https://en.wikipedia.org/wiki/%27No_Way_to_Prevent_This,%27_...