Live data from Hacker News

Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised

safedep.io

311–320 of 329 posts

Re: Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised

#311

Earlier quoted context omitted.

This has nothing to do with standard libraries or popularity. It's about trust. I signed up for an npm account and pushed packages. Same for PyPI. Same for Ruby gems. There's no actual reason why anyone should believe I pushed anything but malware in there.

Did you not read point 3? Developer experience level is a part of the problem.

Yes, and it makes no sense. It's not a "swathe of front-end developers" problem.

Developers in general want to push packages. They don't want to experience friction while doing it. They especially don't want to have to do things like engage with Linux distribution maintainers in order to get their packages into official software repositories. They want to just run $pkgr publish on their repo and that's it. So they invariably end up creating their own distribution mechanisms with zero maintainers involved. Just untrusted randoms making accounts and pushing random stuff. It's easy, so naturally what happens is the repositories get filled with software.

It's only natural to use the stuff that is out there, so the packages get added to projects as dependencies despite the fact none of it is even slightly trusted. Developers hate friction when using libraries too. They very much want to just run $pkgr install x on their repositories and be done with it. They don't want to do things like read the source code or verify that it actually corresponds to what they've downloaded. That's somebody else's problem. On Linux distrubutions, that somebody else is the package maintainer, the exact person the programming language package managers aim to eliminate.

Re: Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised

#312

Earlier quoted context omitted.

Did you not read point 3? Developer experience level is a part of the problem.

Yes, and it makes no sense. It's not a "swathe of front-end developers" problem. Developers in general want to push packages. They don't want to experience friction while doing it. They especially don't want to have to do things like engage with Linux distribution maintainers in order to get their packages into official software repositories. They want to just run $pkgr publish on their repo and that's it. So they in…

> It's only natural to use the stuff that is out there

Sure, if your entire "community" lives and dies by a nonsensical "don't reinvent the wheel, there is a package for that" chant that would rival the most fervent cult members.

Re: Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised

#313

Earlier quoted context omitted.

Pangram says this comment is %100 LLM generated. It certainly reads as LLM generated!

It was.. but not in the way people generally think. Im not a native english speaker. Therefore, I use chatgpt to fix my comment sometimes. This was done the same way.

I get it and I'm not trying to get down on you, but I've seen people around say this and it bugs me.

I don't know Japanese at all. Sometimes I use LLMs to translate discord messages into Japanese so I can communicate with Japanese people. Then as verification I translate the messages back (with different LLMs) and they usually come out as a near-verbatim version of what I wanted to say. In other words, they don't come out in the chatgpt style of writing.

If I'm able to do that, then chatgpt should be able to fix your English without chatgpt-ifying the whole comment.

Re: Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised

#314

Earlier quoted context omitted.

Yes, and it makes no sense. It's not a "swathe of front-end developers" problem. Developers in general want to push packages. They don't want to experience friction while doing it. They especially don't want to have to do things like engage with Linux distribution maintainers in order to get their packages into official software repositories. They want to just run $pkgr publish on their repo and that's it. So they in…

> It's only natural to use the stuff that is out there Sure, if your entire "community" lives and dies by a nonsensical "don't reinvent the wheel, there is a package for that " chant that would rival the most fervent cult members.

That is quite literally the most persistent cargo cult in the entire computing industry. It's the rule, not the exception. Pretty much every community is guilty of it.

Re: Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised

#315

Earlier quoted context omitted.

It was.. but not in the way people generally think. Im not a native english speaker. Therefore, I use chatgpt to fix my comment sometimes. This was done the same way.

I get it and I'm not trying to get down on you, but I've seen people around say this and it bugs me. I don't know Japanese at all. Sometimes I use LLMs to translate discord messages into Japanese so I can communicate with Japanese people. Then as verification I translate the messages back (with different LLMs) and they usually come out as a near-verbatim version of what I wanted to say. In other words, they don't com…

Point accepted. But,

If there are people who focus more on chatgpt "style" of writing, rather than what the message is conveying, frankly, I don't care.

These things are here, they are here to say, and expand into a lot more domains.

Re: Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised

#316
I wonder if npm could run a program where package uploads are automatically delayed for ~10min while they get distributed to an ecosystem of third-party code auditing companies for automatic checks. You could have a public leaderboard of which auditors detect problems fastest and most reliably, or even monetary compensation.

Re: Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised

#317

Earlier quoted context omitted.

Limiting post install as an attack vector is still a good thing. Node is working on a similar permission model to Deno that allows explicitly granting certain system resource permissions https://nodejs.org/api/permissions.html . Using it should help reduce impact from malicious code, though if you allow wide permissions it's unlikely to help.

> Limiting post install as an attack vector is still a good thing. If npm got rid of the post install scripts it would permanently break the install process of packages that use it. Affected systems will need to bypass it, stay on an old npm version, or upgrade the packages to versions that work without post install. Meanwhile, attackers switch to a different attack vector and continue. Who does that help?

I said limit post install, not remove them. Having an allow list in package.json of packages which can run post install would work fine. Pnpm already does this.

Having said that I'm not against full on removal of post install either. It would get more pushback, but would still be possible for people to manually run the post install for the few packages that require it, or to add them as a script in package.json.

Re: Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised

#318
post #163

Earlier quoted context omitted.

at amazon, they maintain a private internal registry of packages with approved licenses and audits. this has been in place for several years. i assume other big corps enforce similar policies

If your company not running an internal proxy at minimum you're stupid - you have no audit function for what libraries are being pulled.

Not every company has tons of available funds to run 300 different internal services to "protect" itself.

Re: Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised

#319
post #307

Earlier quoted context omitted.

It’s one thing to have a conflicting world view. It’s another thing to have the entire Iranian parliament broadcast chanting “death to America”. I’m not even American. I don’t even agree with half the stuff Trump says or does, but I’m onboard with at least 20% of it, and that’s infinitely better than the last bunch of clowns.

If I were to bomb a school near you, you'd hold no grudge?

Come now.

If that school was being used as cover for a military operation by Islamic extremist who recently shot up a music festival I was at, capturing some of the females and raping them then shooting out their eyes and vaginas.

Enough of the false equivocation.

My coffee was a little two hot this morning FUCKING JEWS!

Re: Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised

#320

Earlier quoted context omitted.

Did Claude generate this site? The scroll seems to jump all over the place on my device.

yep... fixed it in new version. Thanks for mentioning.

No worries, works fine on my end now!
Post reply on HN