Live data from Hacker News

You too can run malware from NPM (I mean without consequences)

github.com

121–122 of 122 posts

Re: You too can run malware from NPM (I mean without consequences)

#121

Earlier quoted context omitted.

It seems to be this: https://intel.arkm.com/explorer/entity/61fbc095-f19b-479d-a0... 500 USD, not bad for a month of work if the author is from a 3rd world country.

"3rd world country" is an outdated cold war phrase usually incorrectly used to describe wealth or development status (it originally meant "anything not NATO or Warsaw Pact"); China is a third world country by that merit, but it's the second richest country (by GDP) in the world. "Developing" or "poor" country may be a more accurate phrase.

[deleted]

Re: You too can run malware from NPM (I mean without consequences)

#122
post #30

Earlier quoted context omitted.

Absolutely not. you get npm packages by pulling not them pushing them to you as soon as a new version exist. The likelyhood of you updating instantly is close to zero and if not, you should set your stuff up so that it is. Many ways to do that. Even better if compared to a month or two - which is how long it often takes for a researcher to find a carefully planted malware. Anyway, the case where reactive tools (detec…

I've worked in software supply chain security for two years now and this is an extremely optimistic take. Nearly all organizations are not even remotely close to this level of responsiveness.

Again, that's why LavaMoat exists. Set it up once and it will block many classes of attacks regardless of where they come from.
Post reply on HN