GitLab discovers widespread NPM supply chain attack
about.gitlab.com
GitLab discovers widespread NPM supply chain attack
1–10 of 263 posts
Re: GitLab discovers widespread NPM supply chain attack
#2Re: GitLab discovers widespread NPM supply chain attack
#3Re: GitLab discovers widespread NPM supply chain attack
#4Discussion: https://news.ycombinator.com/item?id=46032539
Re: GitLab discovers widespread NPM supply chain attack
#5Discussion: https://news.ycombinator.com/item?id=46032539
Phew, thought it was another one.
Although it's not entirely new, it's something else.
Re: GitLab discovers widespread NPM supply chain attack
#6Not all the npm packages, but always an npm package
Just like in the 90s when viruses primarily went to windows, it' wasn't some magical property of windows, it was the market of users available.
Also, following this logic, it then becomes survivorship bias, in that the more attacks they get, the more researchers spend time looking & documenting.
Re: GitLab discovers widespread NPM supply chain attack
#7Re: GitLab discovers widespread NPM supply chain attack
#8Not all the npm packages, but always an npm package
While you think this is a producer problem, it's simply a userland market. Just like in the 90s when viruses primarily went to windows, it' wasn't some magical property of windows, it was the market of users available. Also, following this logic, it then becomes survivorship bias, in that the more attacks they get, the more researchers spend time looking & documenting.
Re: GitLab discovers widespread NPM supply chain attack
#9Surely in this day and age we can fairly trivially find out these come from the usual suspects - China, Russia, Iran, etc. Being in such a digital age, where our economies are built on this tech...is this not effectively (economic) warfare? Why are so many governments blase about it?
This can of course be resolved, but here’s the kicker: our own governments equally enjoy this ambiguity to do their own bidding; so no government truly has an incentive to actually improve cross-border identity verification and cybercrime enforcement.
Not to mention, even besides government involvement, these malicious actors still “engage” or induce “engagement” which happens to be the de-facto currency of the technology industry, so even businesses don’t actually have any incentive of fighting them.