Live data from Hacker News

GitLab discovers widespread NPM supply chain attack

about.gitlab.com

1–10 of 263 posts

Re: GitLab discovers widespread NPM supply chain attack

#5
post #4

Discussion: https://news.ycombinator.com/item?id=46032539

Phew, thought it was another one.

> Our internal monitoring system has uncovered multiple infected packages containing what appears to be an evolved version of the "Shai-Hulud" malware.

Although it's not entirely new, it's something else.

Re: GitLab discovers widespread NPM supply chain attack

#6
post #3

Not all the npm packages, but always an npm package

While you think this is a producer problem, it's simply a userland market.

Just like in the 90s when viruses primarily went to windows, it' wasn't some magical property of windows, it was the market of users available.

Also, following this logic, it then becomes survivorship bias, in that the more attacks they get, the more researchers spend time looking & documenting.

Re: GitLab discovers widespread NPM supply chain attack

#7
Surely in this day and age we can fairly trivially find out these come from the usual suspects - China, Russia, Iran, etc. Being in such a digital age, where our economies are built on this tech...is this not effectively (economic) warfare? Why are so many governments blase about it?

Re: GitLab discovers widespread NPM supply chain attack

#8
post #3

Not all the npm packages, but always an npm package

While you think this is a producer problem, it's simply a userland market. Just like in the 90s when viruses primarily went to windows, it' wasn't some magical property of windows, it was the market of users available. Also, following this logic, it then becomes survivorship bias, in that the more attacks they get, the more researchers spend time looking & documenting.

right, npm users. The extreme demand for simple packages and the absent consideration creates an opportunity for attackers to insert "free" solutions. The problem are the 'npm install' happy developers no doubt.

Re: GitLab discovers widespread NPM supply chain attack

#9

Surely in this day and age we can fairly trivially find out these come from the usual suspects - China, Russia, Iran, etc. Being in such a digital age, where our economies are built on this tech...is this not effectively (economic) warfare? Why are so many governments blase about it?

Proving the attack is state-sponsored is difficult (as any attack you attribute to a country can very well be a false-flag operation), and “state sponsorship” is itself a spectrum; for example, you could argue India’s insufficient action against tech-support scammers is effectively state-sanctioned.

This can of course be resolved, but here’s the kicker: our own governments equally enjoy this ambiguity to do their own bidding; so no government truly has an incentive to actually improve cross-border identity verification and cybercrime enforcement.

Not to mention, even besides government involvement, these malicious actors still “engage” or induce “engagement” which happens to be the de-facto currency of the technology industry, so even businesses don’t actually have any incentive of fighting them.

Post reply on HN